Cybersecurity researchers at Securonix have uncovered a sophisticated malware delivery framework, tracked as Veil#Drop, that leverages compromised websites, social engineering tactics, and Google’s trusted Blogspot infrastructure to deploy the PureLog Stealer. This multi-stage attack chain, which combines JavaScript launchers and PowerShell download cradles, represents a deliberate effort to evade traditional security defenses and maintain stealth throughout the infection lifecycle.
Veil#Drop Framework: A Multi-Stage Infection Chain
The Veil#Drop infection begins when a user is tricked into opening a JavaScript file disguised as a legitimate document. This initial script is designed to launch PowerShell code in a way that bypasses standard execution policies. Once executed, the PowerShell component connects to attacker-controlled Blogspot pages to retrieve additional payloads. The use of Blogspot, a trusted Google service, allows the malicious activity to blend in with legitimate web traffic, reducing the likelihood of detection by network security tools.
The first payload retrieved from Blogspot serves a dual purpose: it displays a decoy document to the victim, allaying suspicion, while simultaneously terminating specific processes and decrypting embedded content. This decoded code then generates new Blogspot URLs and executes subsequent payloads directly in memory, a technique known as fileless execution. “A second-stage loader contains XOR-encoded .NET assemblies stored as large embedded data blobs that are reconstructed and decrypted at runtime, preventing straightforward static analysis and reducing the effectiveness of signature-based detection mechanisms,” Securonix explains. The framework also incorporates several fallback mechanisms and abuses trusted Microsoft-signed binaries—a tactic known as living-off-the-land (LOLBIN)—for code execution and defense evasion.
PureLog Stealer: The Final Payload
The culmination of the Veil#Drop infection chain is the deployment of PureLog Stealer, a .NET-based information stealer. Once installed, the malware performs extensive system reconnaissance before beginning the data harvesting process. It targets a wide range of applications, including Google Chrome, Microsoft Edge, Firefox, Brave Browser, Opera, and other Chromium-based browsers. PureLog Stealer is designed to extract credentials, cookies, autofill data, session tokens, browsing histories, and other sensitive information stored within these browsers.
Beyond browser data, the malware searches for cryptocurrency wallet information and can harvest data from messaging applications, email clients, remote access software, FTP clients, cloud storage applications, developer tools, and password managers. All harvested information is packaged and exfiltrated to attacker-controlled servers in an encrypted form, making it difficult to intercept in transit. Given its extensive data-harvesting capabilities, a single infected workstation can become a significant threat to an entire organization.
Enterprise Impact and Broader Security Implications
The Veil#Drop campaign underscores a critical point for enterprise security teams: information stealers are not standalone threats. “In enterprise environments, information stealers are frequently the first stage of larger intrusion campaigns,” Securonix notes. Stolen credentials and session tokens can be leveraged for much more damaging attacks, including ransomware deployment, data theft operations, business email compromise, and long-term espionage. The combination of compromised websites, multi-extension file masquerading, trusted cloud services, XOR-obfuscated payloads, reflective .NET loading, fileless execution, and LOLBIN abuse demonstrates a clear and deliberate effort to circumvent traditional antivirus solutions and reduce forensic artifacts.
What Affected Users and Organizations Should Do Now
While the specific campaign identified by Securonix requires technical investigation to remediate, the nature of the threat demands a broader, precautionary response. Organizations should prioritize deploying multi-layer endpoint protection solutions that include behavioral analysis capabilities, as these are more effective at detecting fileless and in-memory threats than signature-based tools. Users should be educated on the risks of opening unexpected files, particularly those that appear to be documents but have a .js extension, and should be wary of links leading to Blogspot or other blogging platforms from untrusted sources. For individuals who suspect they may have been affected, the immediate steps are to change all passwords from a clean, uninfected device, enable two-factor authentication on all accounts, and closely monitor bank accounts and other financial services for suspicious activity. The use of a reputable no-log VPN service is also strongly recommended, particularly when connecting to business networks from remote or public Wi-Fi, to add an additional layer of encryption and mask the user’s IP address from potential attackers.