VEIL#DROP: Blogger-Hosted Chain Drops PureLogs Stealer
Securonix flags a multi-stage delivery scheme abusing Google's Blogger platform to stage PureLogs, a commodity infostealer sold in underground forums.

Key points
- Securonix has codenamed the activity VEIL#DROP; no named threat cluster has been attributed to it.
- Initial access is assessed at medium confidence as either spear-phishing or drive-by compromise.
- Intermediate scripts are staged on Blogger pages before PureLogs is pulled and executed in memory.
- PureLogs is a .NET infostealer marketed on Russian-language forums since roughly 2022, targeting browser credentials and crypto wallets.
- Detection focus should be on scripting hosts spawning .NET runtimes with outbound connections to Blogger-hosted URIs.
What is VEIL#DROP?
VEIL#DROP is the name Securonix assigned to a multi-stage delivery chain that abuses Google's Blogger platform to host intermediate payloads before dropping PureLogs, a commodity infostealer. Attribution is thin. No named cluster has been tied to the campaign, and the off-the-shelf tooling cuts against high-confidence actor claims.
The initial access vector sits at medium confidence: either spear-phishing or drive-by compromise. That distinction matters. Spear-phishing implies deliberate target selection; drive-by points to opportunistic reach. Available telemetry doesn't yet separate the two cleanly.
Why Blogger?
Blogging platforms offer TLS by default, a trusted parent domain, and content that survives most URL reputation checks. Defenders filtering on domain reputation alone will miss staging traffic to Blogspot subdomains entirely. Similar platform-abuse tradecraft has appeared in past operations by financially motivated loader crews who have parked droppers on GitHub and Discord CDN, though there is no infrastructure overlap suggesting any link to VEIL#DROP specifically.
The choice is increasingly attractive to lower-tier crews. Our 29 June coverage of npm and Go package hijacks documented a parallel instinct: stage through trusted infrastructure and sidestep the reputation filters defenders typically rely on.
Should you worry about PureLogs as the payload?
PureLogs argues against nation-state involvement as the terminal objective. State crews occasionally attach commodity stealers to their kits for deniability, but the more common pattern here points to criminal traffers or initial access brokers monetizing infections directly. Capability does not equal a shared operator: PureLogs is cheap, which is precisely why it surfaces across unrelated intrusion sets.
The multi-stage design, obfuscated loader, remote script pull, in-memory execution, reflects a broader shift away from monolithic droppers. Detection engineers should focus on the parent-child process lineage of scripting hosts spawning .NET runtimes making outbound connections to Blogger-hosted URIs.
What should defenders hunt for now?
Indicators had not been fully published at the time of writing. Hunts worth running: PowerShell or wscript reaching *.blogspot.com with subsequent .NET assembly loads, and any unusual persistence keys pointing to LOLBin execution of remote content.
Call it what it is: a commodity stealer in slightly better packaging. The platform-abuse angle is what defenders should log. The next crew to copy the technique may not be commodity.



