HomeSecurity'Veil#Drop' attacks with payloads hosted on Blogspot

'Veil#Drop' attacks with payloads hosted on Blogspot

Securonix acompany specializing in information security, has uncovered a sophisticated multi-stage malware delivery framework that uses compromised websites and social engineering techniques to infect users with phishing emails. The framework, known as Veil#Drop, is one of the most sophisticated tools discovered recently, combining technologies such as JavaScript and PowerShell to execute malware hosted on trusted infrastructures such as Google’s Blogspot.

See also: Hackers Target Chinese Businesses with Cobalt Strike Payloads

Article Image: Blogspot-Hosted Payloads Delivered in 'Veil#Drop' Attacks

The infection chain begins with a JavaScript file that pretends to be a document. This file is designed to launch PowerShell code, bypassing execution policies that are in place to protect systems. The PowerShell code then retrieves additional payloads from Blogspot pages controlled by the attackers. This use of Blogspot, a platform that is usually considered trustworthy due to its connection to Google, makes Veil#Drop particularly dangerous, as it reduces the likelihood of detection by traditional security systems.

The malicious payload hosted on Blogspot displays a deceptive document, terminates specific processes, and decrypts embedded content. The decrypted code creates additional URLs on Blogspot and executes subsequent payloads directly in system memory. This fileless execution technique makes detection even more difficult, as it leaves no visible traces in the computer's file system.

A second-stage loader contains XOR-encoded .NET assemblies, which are stored as large embedded data. This data is reconstructed and decrypted at runtime, preventing simple static analysis and reducing the effectiveness of signature-based detection mechanisms. This technique makes Veil#Drop highly resistant to traditional malware detection methods.

The sophisticated infection chain also includes several fallback mechanisms, abusing trusted executables signed by Microsoft to execute code and evade detection. This abuse of so-called LOLBINs (Living Off The Land Binaries) allows attackers to exploit existing, trusted tools for malicious activities, further reducing the likelihood of detection.

See also: Amazon Music: 2025 Delivered takes a look back at your musical year

'Veil#Drop' attacks with payloads hosted on Blogspot

Finally, the victim's computer is infected with PureLog Stealer, a .NET-based information stealer that performs system reconnaissance and begins collecting data from various browsers, including Google Chrome, Microsoft Edge, Firefox, Brave Browser, Opera, and other Chromium. The malware targets credentials, cookies, autofill data, session tokens, browsing history, and other sensitive information stored in browsers. It also searches for information about cryptocurrency wallets on the victim's computer.

PureLog Stealer is not limited to browsers. It can also collect information from messaging apps, email clients, remote access software, FTP clients, cloud storage applications, development tools, and password managers. The malware packages the collected information and sends it to servers controlled by the attackers in an encrypted format, making it difficult to detect and analyze the stolen data.

Given the extensive data collection capabilities of PureLog Stealer, a single infected workstation could lead to a broader breach of the environment, depending on the credentials, tokens, keys, and other secrets stored on the system. In enterprise environments, credential stealers are often the first stage of larger intrusion campaigns. Stolen credentials can later be used to deploy ransomware, execute data theft operations, conduct corporate email attacks, or facilitate long-term espionage activities.

See also: AsyncRAT campaign uses Python payloads in attacks

'Veil#Drop' attacks with payloads hosted on Blogspot

The Veil#Drop disclosure by Securonix highlights the need for continued vigilance and security upgrades as attackers continue to evolve their methods to bypass traditional protection solutions. Organizations must invest in advanced detection and response solutions, as well as training staff to recognize and prevent social engineering attacks.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS