[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5kkCgfDZmZt0fzqeaXVgmZiM4eHCeHu6s6yU1bZktXE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"f87070f6-63dc-4ad3-9af7-3bbb8bde9e2a","veildrop-uses-blogspot-and-fileless-powershell-to-deliver-purelog-stealer","22b2bf1e-7501-4fcb-9dbd-edf14f3eed47","Veil#Drop Uses Blogspot and Fileless PowerShell to Deliver PureLog Stealer","The Veil#Drop campaign exploits a combination of social engineering, legitimate hosting platforms (Blogspot), and fileless PowerShell execution to bypass traditional signature-based defenses. By abusing trusted infrastructure like Blogspot, attackers reduce the likelihood of URL-based blocking, while fileless execution leaves minimal disk artifacts for endpoint tools to detect. The ultimate payload, PureLog Stealer, exfiltrates credentials and sensitive data from browsers and messaging applications, which can enable lateral movement and broader network compromise. This attack highlights how adversaries chain together low-suspicion components — a compromised site, a trusted CDN, and native scripting tools — to achieve high-impact outcomes while evading conventional controls.","**Immediate actions:**\n- Block or alert on PowerShell execution policies that allow unsigned or remotely sourced scripts using AppLocker or Windows Defender Application Control.\n- Implement DNS and web filtering rules to flag or block outbound connections to known payload-hosting domains, including unexpected Blogspot URLs.\n- Deploy endpoint detection and response (EDR) tools capable of identifying fileless\u002Fin-memory execution techniques such as reflective PowerShell.\n\n**Long-term improvements:**\n- Enforce the principle of least privilege so that user accounts cannot execute PowerShell or scripting engines without explicit business justification.\n- Conduct regular security awareness training focused on social engineering tactics, including phishing lures that initiate malware download chains.\n- Establish a web proxy with SSL inspection to inspect encrypted traffic to cloud-hosted content platforms used for payload delivery.\n\n**Detection measures:**\n- Enable comprehensive PowerShell script block logging and forward events to a SIEM for anomaly detection on unusual encoded or obfuscated commands.\n- Monitor for credential harvesting indicators such as unexpected access to browser credential stores, clipboard data, or messaging application databases.\n- Set up behavioral analytics alerts for processes spawning network connections to external domains immediately after JavaScript or Office macro execution.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 9: Email and Web Browser Protections","CIS Control 10: Malware Defenses","CIS Control 13: Network Monitoring and Defense","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 AC-6: Least Privilege","NIST SP 800-53 AU-12: Audit Record Generation","NIST SP 800-53 SC-18: Mobile Code","MITRE ATT&CK T1059.001: PowerShell","MITRE ATT&CK T1027: Obfuscated Files or Information","MITRE ATT&CK T1566: Phishing","GDPR Article 32: Security of Processing","published","2026-07-06T20:20:26.505139+00:00","2026-07-06T20:20:26.135+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.securityweek.com\u002Fblogspot-hosted-payloads-delivered-in-veildrop-attacks\u002F","blogspot-hosted-payloads-delivered-in-veil-drop-attacks-63ee79","Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":39,"name":40,"slug":41,"description":42,"color":43},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":45,"name":46,"slug":47,"description":48,"color":49},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]