PureLogs: Delivery via PawsRunner Steganography

Reported 21 May 2026 by otx · Severity: medium

Attackers are concealing .NET infostealers within seemingly innocuous images to evade detection. A phishing campaign uses TXZ archive attachments with invoice-themed lures to initiate infection. The embedded JavaScript leverages environment variables to hide malicious commands, l