Cyble Research and Intelligence Labs (CRIL) has uncovered a sophisticated malware campaign that leverages a commodity loader shared by multiple threat actors.
The ongoing operation targets manufacturing and government organizations in Italy, Finland, and Saudi Arabia, with a primary goal of exfiltrating sensitive industrial data and high-value credentials.
Advanced Delivery Tactics
The attackers deliver the malware through phishing emails disguised as legitimate Purchase Order communications.
The attached RAR or ZIP archives contain malicious JavaScript, LNK shortcuts, or Office documents exploiting CVE-2017-11882 in Microsoft Equation Editor. Once opened, these files trigger a sequence of stealthy payload deliveries.
The infection process involves four stages. A heavily obfuscated JavaScript payload first launches a hidden PowerShell process using Windows Management Instrumentation (WMI).

This script downloads an image file from Archive.org that conceals a malicious .NET assembly in its pixel data via steganography. The payload is extracted in memory, avoiding disk writes and evading detection.
In the next stage, a trojanized version of the open-source TaskScheduler library, modified to include malicious code, is loaded reflectively.
It retrieves encoded payloads, reverses and decodes them, and injects them into legitimate Windows processes, such as RegAsm.exe, via process hollowing. This approach allows the malware to execute under trusted system binaries and bypass traditional security tools.
Stealthy Execution and Data Theft
The final payload analyzed by CRIL includes PureLog Stealer, an information stealer that harvests browser credentials, cryptocurrency wallet data, VPN configuration files, and email client credentials.
Stolen data is transmitted to the attacker’s command-and-control (C2) server at 38.49.210[.]241. Researchers also discovered a novel User Account Control (UAC) bypass technique.
The malware monitors system processes and triggers a UAC prompt during legitimate application launches, tricking users into unknowingly granting elevated privileges. This behavior underscores the threat’s advanced evasion design.
Cyble’s analysis links identical loader artifacts across multiple campaigns, suggesting a shared infrastructure or malware-as-a-service ecosystem.
Other security firms, including Seqrite, Nextron Systems, and Zscaler, have observed similar loader characteristics across RATs and stealers, including PureLog, Katz Stealer, DC Rat, Async Rat, and Remcos.
CRIL urges organizations in the manufacturing and industrial sectors to tighten email security, restrict script execution, and adopt EDR solutions that detect memory-based threats.
Additionally, image files from untrusted sources should be analyzed for hidden data, as attackers increasingly use steganography to conceal malicious payloads.
Follow us on Google News , LinkedIn and X to Get More Instant Updates, Set Cyberpress as a Preferred Source in Google.