PureRAT and PureLogs Campaign Targeting Japanese Organizations
Between July and August 2026, a sophisticated campaign targeted organizations across East and Southeast Asia using Japanese and Korean-language phishing emails disguised as product damage complaints. Recipients were directed to fake document-sharing websites that delivered ZIP files containing malware. The archives contained executables with double extensions and DLLs implementing various loader techniques including customized Donut loaders, Python interpreters, AMSI/ETW bypasses, process hollowing, and BYOVD attacks using vulnerable Lenovo drivers. Despite varying loader implementations, the final payloads consistently delivered PureRAT or PureLogs malware families. The campaign demonstrated advanced evasion techniques by frequently changing loader structures while maintaining the same core payloads, effectively bypassing hash-based detection methods. Infrastructure analysis revealed common sending patterns through PHP Swift Mailer and shared Feedback-ID values across campaigns.
AI Analysis
Technical Summary
This campaign used phishing emails in Japanese and Korean languages to lure targets to malicious document-sharing websites hosting ZIP archives with malware. The malware loaders employed multiple sophisticated evasion techniques including customized Donut loaders, Python interpreters, AMSI and ETW bypasses, process hollowing, and Bring Your Own Vulnerable Driver (BYOVD) attacks exploiting Lenovo driver vulnerabilities. Despite variations in loader implementations, the payloads consistently deployed PureRAT and PureLogs malware families. The campaign demonstrated operational security by frequently changing loader structures to bypass hash-based detection methods. Infrastructure analysis revealed consistent use of PHP Swift Mailer and shared Feedback-ID values, indicating coordinated campaign infrastructure.
Potential Impact
The campaign delivers PureRAT and PureLogs malware, which are known for information stealing and remote access capabilities. The use of advanced loader and evasion techniques increases the likelihood of successful infection and persistence on targeted systems. The campaign targets organizations in East and Southeast Asia, potentially compromising sensitive data and operational security. The frequent changes in loader structures complicate detection and response efforts.
Mitigation Recommendations
No vendor advisory or patch information is provided for this campaign. Mitigation should focus on user awareness to recognize phishing emails disguised as product damage complaints, blocking access to known malicious document-sharing websites, and deploying endpoint detection solutions capable of identifying advanced loader techniques such as process hollowing and BYOVD attacks. Monitoring for indicators related to PHP Swift Mailer usage and Feedback-ID values may assist in identifying related activity. Since no patch or official fix is indicated, organizations should apply layered defenses and maintain updated threat intelligence.
Indicators of Compromise
- domain: baoquocgiavn.com
- domain: bayareakajabe.com
- domain: bartonaussies.com
- ip: 103.153.74.201
- ip: 103.179.188.236
- hash: 82699276b0f59a2304120a6baaf64a6b
- hash: 5ab36c116767eaae53a466fbc2dae7cfd608ed77721f65e83312037fbd57c946
- hash: 87903559afa09a0dfe251598c14e58124bddde1d
- domain: tirakian.com
- hash: 1fdea279cb8c9217487ac4c86ae9316c
- hash: 2e05d97ed7bfabea8f7370ba627e0705ec2c0fbf3974b39437e9d95d45d1a76d
- domain: shareddocumentdrivehub.com
- url: https://shareddocumentdrivehub.com/Full_Unboxing_Process_Inspection_Record_333_2026.docx/views/xlqpmvcznaert
- domain: sharedocumentsystem.com
- url: https://sharedocumentsystem.com/Full_Unboxing_Process_Inspection_Record_333_2026.docx/views/xlqpmzncvaret
- domain: drive.careernetwork.co.nz
- domain: logs.uvexio.com
- domain: tea.vexexo.com
- domain: customerreviewproduct.com
- domain: customersrespondedpositively.com
- url: https://customersrespondedpositively.com/Complete_Unboxing_And_Damage_Inspection.mp4/views/PqsTVwXyZatii
- domain: trump2.1368.lol
- domain: cloudflare.carriernetworks.top
- domain: pure26.myftp.org
- hash: 719f689b34f47be8ca105ce8484948474dafde0e106bab599e4a89326070c3d0
- ip: 103.82.26.183
- ip: 103.179.189.169
- ip: 103.82.20.17
- ip: 103.179.188.216
- ip: 103.179.188.9
- ip: 103.82.20.60
- hash: 05e27e1a0ed75c32e896c5d0261bb077
- hash: 6624eb2d2637338c82b5325141f1f75179a74660
- hash: af4ee79582992e348a8739579da478d50daccbaa6ec97420311916a2ac0fc503
- url: https://globaldocumentsharingcenter.com/Full_Unboxing_Process_Inspection_Record_333_2026.docx/views/zxczcczlkcjaslda
- url: https://documentcloudlink.com/Complete_Unboxing_And_Damage_Inspection.mp4/views/mxqvcznplrtei
- url: https://drive.careernetwork.co.nz/download.php/Complete_Unboxing_And_Damage_Inspection?f=6d90494c1119bb8cc67a85a9ac9aeaca
- url: https://drbox.august-brokers.co.nz/download.php/Package_Condition_Recordingmp4?f=5331793d7c89907eeff77081d021d10d
- url: https://customerreviewproduct.com/Complete_Unboxing_And_Damage_Inspection.mp4/views/iOpLkJhGfDsAtp
- url: https://cloudflare.carriernetworks.top/?sharingcenterDelivery_Unboxing_Verification.MP4
- ip: 103.153.75.131
- hash: e55412555b4699c6d3ce2ac60df81eb1ee0d5aa412a303555c8f64037d5633d0
- hash: c1a2b48d4f639b46cf6cde8322666f0991531ef32ffe571140418ae40342ffe8
- hash: 8cd271f946d84423c554992eb0176be395cdd7bf6179efe1822759d019c94f34
- hash: eb20fb4e1de2844717270e600af05abac06b359be711eabf14a3d91bfbf966e6
- hash: ad0c3182b18b5d7ba8771d830f4d51b4ada7e26f8d05223f4379e6312aba65fa
- hash: 9e54486f204d8c9ff9c539c5b2119b79a6da21e3dfdb7f51ee8ebba62f851174
- hash: 1b5cf526a28bae9283acf91b2c0ccae3163d24706e40d9a0aea38c4b79e65d36
- hash: 567fc6e35bb45a6ecf5d870e454c813613032078a5ba01fcd374544930598703
- hash: aee2aefbc73dbf5f65e455ef18e74e158290e21803bf3dd64a05d087bfaceb18
- hash: afd31f096c93776888454e1321654477cfd97eb0c6a75bea624d8f7d891e0a61
- domain: globaldocumentsharingcenter.com
- hash: 5331793d7c89907eeff77081d021d10d
- hash: 6d90494c1119bb8cc67a85a9ac9aeaca
- hash: 79435213ab241b13a9d8da354c088868
- hash: e951e6e4ef4a2696c69306693abd4a0e
- hash: 1f655ff488320c589cb50f8ffe2701f7208999fe
- hash: 6232326f3da33c340c57e7370e038085d5f86d88
- hash: f58f4bc7e421bb2e1117c22a8acf120de388d442
- hash: 1be5cfb6b0e2ed8cf2c63365213f8a58f1a75e93899e7018acfa6b3484e8baa0
- url: https://shareddocumentdrivehub.com/create.php.
- domain: documentcloudlink.com
- domain: azuravenue.com
- domain: babiesolutions.com
- domain: bagsdar.com
- domain: banksgreenanimals.com
- domain: baoholaodongbaoanh.com
- domain: baqtalanaqh.com
- domain: api0709.azuravenue.com
- domain: api0714.babilkuruyemis.com
- domain: api0727.banvanchuyen.com
- domain: api0728.baoholaodongbaoanh.com
- domain: api0728.baptizedinchrist.com
- domain: api0728.baqtalanaqh.com
- domain: api0730.bartonaussies.com
- domain: api0731.bayraqaleud.com
- domain: brevo20.badgersweeteners.com
- domain: drbox.august-brokers.co.nz
PureRAT and PureLogs Campaign Targeting Japanese Organizations
Description
Between July and August 2026, a sophisticated campaign targeted organizations across East and Southeast Asia using Japanese and Korean-language phishing emails disguised as product damage complaints. Recipients were directed to fake document-sharing websites that delivered ZIP files containing malware. The archives contained executables with double extensions and DLLs implementing various loader techniques including customized Donut loaders, Python interpreters, AMSI/ETW bypasses, process hollowing, and BYOVD attacks using vulnerable Lenovo drivers. Despite varying loader implementations, the final payloads consistently delivered PureRAT or PureLogs malware families. The campaign demonstrated advanced evasion techniques by frequently changing loader structures while maintaining the same core payloads, effectively bypassing hash-based detection methods. Infrastructure analysis revealed common sending patterns through PHP Swift Mailer and shared Feedback-ID values across campaigns.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign used phishing emails in Japanese and Korean languages to lure targets to malicious document-sharing websites hosting ZIP archives with malware. The malware loaders employed multiple sophisticated evasion techniques including customized Donut loaders, Python interpreters, AMSI and ETW bypasses, process hollowing, and Bring Your Own Vulnerable Driver (BYOVD) attacks exploiting Lenovo driver vulnerabilities. Despite variations in loader implementations, the payloads consistently deployed PureRAT and PureLogs malware families. The campaign demonstrated operational security by frequently changing loader structures to bypass hash-based detection methods. Infrastructure analysis revealed consistent use of PHP Swift Mailer and shared Feedback-ID values, indicating coordinated campaign infrastructure.
Potential Impact
The campaign delivers PureRAT and PureLogs malware, which are known for information stealing and remote access capabilities. The use of advanced loader and evasion techniques increases the likelihood of successful infection and persistence on targeted systems. The campaign targets organizations in East and Southeast Asia, potentially compromising sensitive data and operational security. The frequent changes in loader structures complicate detection and response efforts.
Defensive Guidance
No vendor advisory or patch information is provided for this campaign. Mitigation should focus on user awareness to recognize phishing emails disguised as product damage complaints, blocking access to known malicious document-sharing websites, and deploying endpoint detection solutions capable of identifying advanced loader techniques such as process hollowing and BYOVD attacks. Monitoring for indicators related to PHP Swift Mailer usage and Feedback-ID values may assist in identifying related activity. Since no patch or official fix is indicated, organizations should apply layered defenses and maintain updated threat intelligence.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://blog-en.itochuci.co.jp/entry/2026/09/25/090000"]
- Pulse Id
- 6ab69627dd56b82f3b52796d
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainbaoquocgiavn.com | — | |
domainbayareakajabe.com | — | |
domainbartonaussies.com | — | |
domaintirakian.com | — | |
domainshareddocumentdrivehub.com | — | |
domainsharedocumentsystem.com | — | |
domaindrive.careernetwork.co.nz | — | |
domainlogs.uvexio.com | — | |
domaintea.vexexo.com | — | |
domaincustomerreviewproduct.com | — | |
domaincustomersrespondedpositively.com | — | |
domaintrump2.1368.lol | — | |
domaincloudflare.carriernetworks.top | — | |
domainpure26.myftp.org | — | |
domainglobaldocumentsharingcenter.com | — | |
domaindocumentcloudlink.com | — | |
domainazuravenue.com | — | |
domainbabiesolutions.com | — | |
domainbagsdar.com | — | |
domainbanksgreenanimals.com | — | |
domainbaoholaodongbaoanh.com | — | |
domainbaqtalanaqh.com | — | |
domainapi0709.azuravenue.com | — | |
domainapi0714.babilkuruyemis.com | — | |
domainapi0727.banvanchuyen.com | — | |
domainapi0728.baoholaodongbaoanh.com | — | |
domainapi0728.baptizedinchrist.com | — | |
domainapi0728.baqtalanaqh.com | — | |
domainapi0730.bartonaussies.com | — | |
domainapi0731.bayraqaleud.com | — | |
domainbrevo20.badgersweeteners.com | — | |
domaindrbox.august-brokers.co.nz | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip103.153.74.201 | — | |
ip103.179.188.236 | — | |
ip103.82.26.183 | — | |
ip103.179.189.169 | — | |
ip103.82.20.17 | — | |
ip103.179.188.216 | — | |
ip103.179.188.9 | — | |
ip103.82.20.60 | — | |
ip103.153.75.131 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash82699276b0f59a2304120a6baaf64a6b | — | |
hash5ab36c116767eaae53a466fbc2dae7cfd608ed77721f65e83312037fbd57c946 | — | |
hash87903559afa09a0dfe251598c14e58124bddde1d | — | |
hash1fdea279cb8c9217487ac4c86ae9316c | — | |
hash2e05d97ed7bfabea8f7370ba627e0705ec2c0fbf3974b39437e9d95d45d1a76d | — | |
hash719f689b34f47be8ca105ce8484948474dafde0e106bab599e4a89326070c3d0 | — | |
hash05e27e1a0ed75c32e896c5d0261bb077 | — | |
hash6624eb2d2637338c82b5325141f1f75179a74660 | — | |
hashaf4ee79582992e348a8739579da478d50daccbaa6ec97420311916a2ac0fc503 | — | |
hashe55412555b4699c6d3ce2ac60df81eb1ee0d5aa412a303555c8f64037d5633d0 | — | |
hashc1a2b48d4f639b46cf6cde8322666f0991531ef32ffe571140418ae40342ffe8 | — | |
hash8cd271f946d84423c554992eb0176be395cdd7bf6179efe1822759d019c94f34 | — | |
hasheb20fb4e1de2844717270e600af05abac06b359be711eabf14a3d91bfbf966e6 | — | |
hashad0c3182b18b5d7ba8771d830f4d51b4ada7e26f8d05223f4379e6312aba65fa | — | |
hash9e54486f204d8c9ff9c539c5b2119b79a6da21e3dfdb7f51ee8ebba62f851174 | — | |
hash1b5cf526a28bae9283acf91b2c0ccae3163d24706e40d9a0aea38c4b79e65d36 | — | |
hash567fc6e35bb45a6ecf5d870e454c813613032078a5ba01fcd374544930598703 | — | |
hashaee2aefbc73dbf5f65e455ef18e74e158290e21803bf3dd64a05d087bfaceb18 | — | |
hashafd31f096c93776888454e1321654477cfd97eb0c6a75bea624d8f7d891e0a61 | — | |
hash5331793d7c89907eeff77081d021d10d | — | |
hash6d90494c1119bb8cc67a85a9ac9aeaca | — | |
hash79435213ab241b13a9d8da354c088868 | — | |
hashe951e6e4ef4a2696c69306693abd4a0e | — | |
hash1f655ff488320c589cb50f8ffe2701f7208999fe | — | |
hash6232326f3da33c340c57e7370e038085d5f86d88 | — | |
hashf58f4bc7e421bb2e1117c22a8acf120de388d442 | — | |
hash1be5cfb6b0e2ed8cf2c63365213f8a58f1a75e93899e7018acfa6b3484e8baa0 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://shareddocumentdrivehub.com/Full_Unboxing_Process_Inspection_Record_333_2026.docx/views/xlqpmvcznaert | — | |
urlhttps://sharedocumentsystem.com/Full_Unboxing_Process_Inspection_Record_333_2026.docx/views/xlqpmzncvaret | — | |
urlhttps://customersrespondedpositively.com/Complete_Unboxing_And_Damage_Inspection.mp4/views/PqsTVwXyZatii | — | |
urlhttps://globaldocumentsharingcenter.com/Full_Unboxing_Process_Inspection_Record_333_2026.docx/views/zxczcczlkcjaslda | — | |
urlhttps://documentcloudlink.com/Complete_Unboxing_And_Damage_Inspection.mp4/views/mxqvcznplrtei | — | |
urlhttps://drive.careernetwork.co.nz/download.php/Complete_Unboxing_And_Damage_Inspection?f=6d90494c1119bb8cc67a85a9ac9aeaca | — | |
urlhttps://drbox.august-brokers.co.nz/download.php/Package_Condition_Recordingmp4?f=5331793d7c89907eeff77081d021d10d | — | |
urlhttps://customerreviewproduct.com/Complete_Unboxing_And_Damage_Inspection.mp4/views/iOpLkJhGfDsAtp | — | |
urlhttps://cloudflare.carriernetworks.top/?sharingcenterDelivery_Unboxing_Verification.MP4 | — | |
urlhttps://shareddocumentdrivehub.com/create.php. | — |
Threat ID: 6aba7398f7a7c54106c46231
Added to database: 09/28/2026, 14:03:04 UTC
Last enriched: 09/28/2026, 14:18:29 UTC
Last updated: 09/29/2026, 02:49:02 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.