Attackers Are Turning Everyday Business Emails Into Malware Delivery Machines
A 2026 email campaign used damage and refund lures to deliver PureRAT and PureLogs via fake download sites.
ITOCHU Cyber & Intelligence reported a July–August 2026 campaign that emailed Japanese and Korean organizations about damaged goods, shipping problems, and refunds. Links led to multilingual fake document-sharing or video sites that offered ZIP archives hiding executables, including double-extension files and a malicious DLL loaded by a Microsoft-signed program. Loaders varied, including bundled Python, a modified Donut loader, and in-memory execution, with persistence through startup shortcuts, scheduled tasks, or the registry. Payloads were PureRAT, a remote access tool, and PureLogs, an infostealer collecting browser data, Discord information, screenshots, and files; one variant used a signed vulnerable driver to kill security processes.