← Back to Feed

Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data

May 26, 2026 · Fortinet Threat Research · Severity: LOW

FortiGuard Labs has uncovered a sophisticated phishing campaign leveraging obfuscated JavaScript, PowerShell, process hollowing, and a PureLogs variant to steal sensitive data. The attackers deploy malicious JavaScript code embedded in phishing emails, which initiates a chain of events leading to the execution of PowerShell scripts. These scripts then employ process hollowing—a technique that replaces legitimate process memory with malicious code—to evade detection. The campaign ultimately installs PureLogs, a data-stealing malware variant, to harvest credentials, browser histories, and other sensitive information from compromised systems. The campaign primarily targets individuals and organizations across various sectors, aiming to exfiltrate valuable data for financial gain or espionage. The use of advanced techniques like process hollowing and obfuscation makes detection challenging for traditional security tools. This campaign highlights the evolving tactics of cybercriminals, emphasizing the need for robust email security, endpoint protection, and user awareness training. Organizations are urged to monitor for suspicious PowerShell activity and implement multi-layered defenses to mitigate such threats.

FortiGuard Labs analyzed a new phishing campaign that uses obfuscated JavaScript, PowerShell, process hollowing, and PureLogs to steal sensitive data

      

Key Takeaways

  • A phishing campaign deploys a JavaScript-driven PureLogs variant to steal sensitive credentials and data from compromised systems.
  • Organizations should deploy email security filters and train employees to recognize phishing lures that deliver JavaScript-based malware.
  • Organizations should review the full article for complete details and implement relevant security measures.
☕ Buy a Coffee