Fake Purchase Order Emails Spread Fileless PureLogs Malware via RAR Archives

https://hackread.com/wp-content/uploads/2026/06/purchase-emails-fileless-purelogs-malware-rar-archives-1024x576.png

FortiGuard Labs has disclosed its findings about a new email campaign targeting Windows users with a malicious data-stealing program called PureLogs. According to their research, the attack begins with fake purchase order emails that trick targets into opening a malicious archive named “PO 2026-P0803.rar” as an initial trap.

After this, a hidden script called “kpankocrs.js” runs automatically and drops a randomly named file like "ps_qnSEGUkU0LIY_1777592585573.ps1” into the "C:\Temp" folder. It uses the Windows script engine (wscript.exe) to trigger PowerShell.exe and bypass system restrictions.

Process hollowing helps hackers avoid detection. In this technique, a genuine program is hijacked to hide the malware, which, in this case, is a legitimate Windows process at "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MsBuild.exe.” Its safe code is replaced with a malicious downloader module.

Researchers further noted that this hijackrelies on specific system commands to trick the computer. The malware calls CreateProcessA() to open the safe program in a frozen...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more