# PureLogs Infostealer Spreads via Cat Photo Steganography

**Published:** 2026-05-15T13:00:00.000Z  
**Topic:** Polkadot  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/a51e2427-cd5c-47c9-b196-3b16ee1feeed

A new phishing campaign is distributing the PureLogs infostealer by hiding malicious payloads inside cat images to bypass security detection systems.

A phishing campaign is currently distributing the PureLogs information stealer by concealing encrypted malicious payloads within image files, a technique known as steganography [1]. Researchers at Fortinet discovered that the attackers are using cat photos to smuggle the malware onto Windows systems, allowing the malicious traffic to blend in with legitimate network activity [1].

**Key takeaways**
* The attack begins with a phishing email containing an invoice-themed lure and a TXZ archive [1].
* Malicious payloads are hidden inside PNG image files using steganography markers to evade security alarms [1].
* The PureLogs infostealer harvests credentials, cookies, and session tokens from web browsers, crypto wallets, and communication apps [1].
* The malware uses HTTPS for command and control communications and employs async/await patterns to complicate security analysis [1].

## The Mechanics of the PawsRunner Delivery
The infection process initiates when a victim opens a TXZ archive attached to a phishing email [1]. Once extracted, a JavaScript file executes, using obfuscated process environment variables to launch a hidden PowerShell session [1]. This session is responsible for decoding and decompressing a .NET assembly loader identified as PawsRunner [1].

PawsRunner functions by decrypting a download URL using the RC4 algorithm and subsequently fetching a PNG image file [1]. By utilizing steganography, the attackers embed the final PureLogs payload within the image, a method that is increasingly popular because it avoids the scrutiny often applied to direct executable downloads [1]. Once the payload is extracted, the malware bypasses Windows 11 security features and Event Tracing for Windows to establish its presence on the host machine [1].

## Data Exfiltration and System Impact
Once active, PureLogs profiles the compromised system to harvest sensitive information [1]. The infostealer targets a wide array of software, including over 100 crypto wallet extensions, various password managers, and communication platforms such as Telegram, Discord, and Signal [1]. It also extracts data from common desktop applications like Steam, FileZilla, and Outlook [1].

The stolen data is encrypted using AES before being exfiltrated to the attackers [1]. According to the researchers, this information can be used for direct financial theft or sold on criminal markets, potentially facilitating further attacks against the victim’s employer or personal contacts [1].

## Why it matters
The use of steganography represents a deliberate shift in tactics designed to make malicious downloads appear as benign network traffic [1]. Because PNG files fetched over HTTPS are less likely to trigger security alerts than traditional executables, this method poses a significant challenge for standard endpoint protection [1]. Security experts advise organizations to block uncommon archive formats at email gateways, restrict JavaScript execution from attachments, and monitor for unusual PowerShell behavior to mitigate the risk of such campaigns [1].

## Sources
1. Helpnetsecurity — [PureLogs infostealer is stealing credentials worldwide - Help](https://www.helpnetsecurity.com/2026/05/19/purelogs-infostealer-delivery-steganography/)
2. Lucadonettidontin — [Meinberg Syslog via TLS – Luca Donetti Dontin](https://www.lucadonettidontin.it/meinberg-syslog-via-tls/)

---
Cite as: TrendWatcher, "PureLogs Infostealer Spreads via Cat Photo Steganography", https://www.trendwatcher.in/article/a51e2427-cd5c-47c9-b196-3b16ee1feeed
