Skip to main content

PureRAT and PureLogs Campaign Targeting Japanese Organizations

0
Medium
Published: 09/25/2026 (09/25/2026, 15:41:27 UTC)
Source: AlienVault OTX General

Description

Between July and August 2026, a sophisticated campaign targeted organizations across East and Southeast Asia using Japanese and Korean-language phishing emails disguised as product damage complaints. Recipients were directed to fake document-sharing websites that delivered ZIP files containing malware. The archives contained executables with double extensions and DLLs implementing various loader techniques including customized Donut loaders, Python interpreters, AMSI/ETW bypasses, process hollowing, and BYOVD attacks using vulnerable Lenovo drivers. Despite varying loader implementations, the final payloads consistently delivered PureRAT or PureLogs malware families. The campaign demonstrated advanced evasion techniques by frequently changing loader structures while maintaining the same core payloads, effectively bypassing hash-based detection methods. Infrastructure analysis revealed common sending patterns through PHP Swift Mailer and shared Feedback-ID values across campaigns.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/28/2026, 14:18:29 UTC

Technical Analysis

This campaign used phishing emails in Japanese and Korean languages to lure targets to malicious document-sharing websites hosting ZIP archives with malware. The malware loaders employed multiple sophisticated evasion techniques including customized Donut loaders, Python interpreters, AMSI and ETW bypasses, process hollowing, and Bring Your Own Vulnerable Driver (BYOVD) attacks exploiting Lenovo driver vulnerabilities. Despite variations in loader implementations, the payloads consistently deployed PureRAT and PureLogs malware families. The campaign demonstrated operational security by frequently changing loader structures to bypass hash-based detection methods. Infrastructure analysis revealed consistent use of PHP Swift Mailer and shared Feedback-ID values, indicating coordinated campaign infrastructure.

Potential Impact

The campaign delivers PureRAT and PureLogs malware, which are known for information stealing and remote access capabilities. The use of advanced loader and evasion techniques increases the likelihood of successful infection and persistence on targeted systems. The campaign targets organizations in East and Southeast Asia, potentially compromising sensitive data and operational security. The frequent changes in loader structures complicate detection and response efforts.

Defensive Guidance

No vendor advisory or patch information is provided for this campaign. Mitigation should focus on user awareness to recognize phishing emails disguised as product damage complaints, blocking access to known malicious document-sharing websites, and deploying endpoint detection solutions capable of identifying advanced loader techniques such as process hollowing and BYOVD attacks. Monitoring for indicators related to PHP Swift Mailer usage and Feedback-ID values may assist in identifying related activity. Since no patch or official fix is indicated, organizations should apply layered defenses and maintain updated threat intelligence.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://blog-en.itochuci.co.jp/entry/2026/09/25/090000"]
Pulse Id
6ab69627dd56b82f3b52796d

Indicators of Compromise

Domain

ValueDescriptionCopy
domainbaoquocgiavn.com
—
domainbayareakajabe.com
—
domainbartonaussies.com
—
domaintirakian.com
—
domainshareddocumentdrivehub.com
—
domainsharedocumentsystem.com
—
domaindrive.careernetwork.co.nz
—
domainlogs.uvexio.com
—
domaintea.vexexo.com
—
domaincustomerreviewproduct.com
—
domaincustomersrespondedpositively.com
—
domaintrump2.1368.lol
—
domaincloudflare.carriernetworks.top
—
domainpure26.myftp.org
—
domainglobaldocumentsharingcenter.com
—
domaindocumentcloudlink.com
—
domainazuravenue.com
—
domainbabiesolutions.com
—
domainbagsdar.com
—
domainbanksgreenanimals.com
—
domainbaoholaodongbaoanh.com
—
domainbaqtalanaqh.com
—
domainapi0709.azuravenue.com
—
domainapi0714.babilkuruyemis.com
—
domainapi0727.banvanchuyen.com
—
domainapi0728.baoholaodongbaoanh.com
—
domainapi0728.baptizedinchrist.com
—
domainapi0728.baqtalanaqh.com
—
domainapi0730.bartonaussies.com
—
domainapi0731.bayraqaleud.com
—
domainbrevo20.badgersweeteners.com
—
domaindrbox.august-brokers.co.nz
—

Ip

ValueDescriptionCopy
ip103.153.74.201
—
ip103.179.188.236
—
ip103.82.26.183
—
ip103.179.189.169
—
ip103.82.20.17
—
ip103.179.188.216
—
ip103.179.188.9
—
ip103.82.20.60
—
ip103.153.75.131
—

Hash

ValueDescriptionCopy
hash82699276b0f59a2304120a6baaf64a6b
—
hash5ab36c116767eaae53a466fbc2dae7cfd608ed77721f65e83312037fbd57c946
—
hash87903559afa09a0dfe251598c14e58124bddde1d
—
hash1fdea279cb8c9217487ac4c86ae9316c
—
hash2e05d97ed7bfabea8f7370ba627e0705ec2c0fbf3974b39437e9d95d45d1a76d
—
hash719f689b34f47be8ca105ce8484948474dafde0e106bab599e4a89326070c3d0
—
hash05e27e1a0ed75c32e896c5d0261bb077
—
hash6624eb2d2637338c82b5325141f1f75179a74660
—
hashaf4ee79582992e348a8739579da478d50daccbaa6ec97420311916a2ac0fc503
—
hashe55412555b4699c6d3ce2ac60df81eb1ee0d5aa412a303555c8f64037d5633d0
—
hashc1a2b48d4f639b46cf6cde8322666f0991531ef32ffe571140418ae40342ffe8
—
hash8cd271f946d84423c554992eb0176be395cdd7bf6179efe1822759d019c94f34
—
hasheb20fb4e1de2844717270e600af05abac06b359be711eabf14a3d91bfbf966e6
—
hashad0c3182b18b5d7ba8771d830f4d51b4ada7e26f8d05223f4379e6312aba65fa
—
hash9e54486f204d8c9ff9c539c5b2119b79a6da21e3dfdb7f51ee8ebba62f851174
—
hash1b5cf526a28bae9283acf91b2c0ccae3163d24706e40d9a0aea38c4b79e65d36
—
hash567fc6e35bb45a6ecf5d870e454c813613032078a5ba01fcd374544930598703
—
hashaee2aefbc73dbf5f65e455ef18e74e158290e21803bf3dd64a05d087bfaceb18
—
hashafd31f096c93776888454e1321654477cfd97eb0c6a75bea624d8f7d891e0a61
—
hash5331793d7c89907eeff77081d021d10d
—
hash6d90494c1119bb8cc67a85a9ac9aeaca
—
hash79435213ab241b13a9d8da354c088868
—
hashe951e6e4ef4a2696c69306693abd4a0e
—
hash1f655ff488320c589cb50f8ffe2701f7208999fe
—
hash6232326f3da33c340c57e7370e038085d5f86d88
—
hashf58f4bc7e421bb2e1117c22a8acf120de388d442
—
hash1be5cfb6b0e2ed8cf2c63365213f8a58f1a75e93899e7018acfa6b3484e8baa0
—

Url

ValueDescriptionCopy
urlhttps://shareddocumentdrivehub.com/Full_Unboxing_Process_Inspection_Record_333_2026.docx/views/xlqpmvcznaert
—
urlhttps://sharedocumentsystem.com/Full_Unboxing_Process_Inspection_Record_333_2026.docx/views/xlqpmzncvaret
—
urlhttps://customersrespondedpositively.com/Complete_Unboxing_And_Damage_Inspection.mp4/views/PqsTVwXyZatii
—
urlhttps://globaldocumentsharingcenter.com/Full_Unboxing_Process_Inspection_Record_333_2026.docx/views/zxczcczlkcjaslda
—
urlhttps://documentcloudlink.com/Complete_Unboxing_And_Damage_Inspection.mp4/views/mxqvcznplrtei
—
urlhttps://drive.careernetwork.co.nz/download.php/Complete_Unboxing_And_Damage_Inspection?f=6d90494c1119bb8cc67a85a9ac9aeaca
—
urlhttps://drbox.august-brokers.co.nz/download.php/Package_Condition_Recordingmp4?f=5331793d7c89907eeff77081d021d10d
—
urlhttps://customerreviewproduct.com/Complete_Unboxing_And_Damage_Inspection.mp4/views/iOpLkJhGfDsAtp
—
urlhttps://cloudflare.carriernetworks.top/?sharingcenterDelivery_Unboxing_Verification.MP4
—
urlhttps://shareddocumentdrivehub.com/create.php.
—

Threat ID: 6aba7398f7a7c54106c46231

Added to database: 09/28/2026, 14:03:04 UTC

Last enriched: 09/28/2026, 14:18:29 UTC

Last updated: 09/29/2026, 02:49:02 UTC

Views: 15

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses