Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data

Reported 26 May 2026 by otx · Severity: medium

A sophisticated phishing campaign distributes a PureLogs variant through deceptive purchase order emails containing malicious JavaScript files. The attack chain employs obfuscated JavaScript that drops PowerShell scripts, which then use process hollowing techniques to inject .NET