{"id":1127,"date":"2026-08-19T20:10:44","date_gmt":"2026-08-19T14:40:44","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1127"},"modified":"2026-08-19T20:12:01","modified_gmt":"2026-08-19T14:42:01","slug":"veil-malware-explained","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/veil-malware-explained\/","title":{"rendered":"Veil Malware: How Attackers Use Blogspot to Deliver Fileless Payloads"},"content":{"rendered":"<p>A newly disclosed malware delivery framework known as Veil demonstrates how attackers are combining trusted cloud infrastructure, fileless execution, and multi-stage payload delivery to make endpoint compromise harder to detect. Rather than relying on a single malicious executable, the campaign chains together compromised websites, JavaScript, PowerShell, and Blogspot-hosted payloads to quietly deliver the PureLog information stealer while minimizing traditional forensic evidence.<\/p>\n<p>For enterprise security teams, the significance extends beyond another malware family. The veil malware campaign illustrates a broader shift in attacker tradecraft: legitimate services and trusted binaries are increasingly being used to bypass conventional security controls, forcing organizations to strengthen visibility across script execution, identity, endpoint behavior, and network activity instead of relying solely on reputation-based detection.<\/p>\n<h2>How the Veil Attack Chain Works<\/h2>\n<p>The Veil malware (also referred to by Securonix as VEIL#DROP) campaign uses a layered execution chain that prioritizes stealth, trusted infrastructure, and in-memory execution over conventional malware delivery. Instead of delivering the final payload directly, each stage prepares the environment for the next, making the attack more resilient against signature-based detection and static analysis.<\/p>\n<h3>Stage 1: Initial Access<\/h3>\n<p>The attack begins with a JavaScript file disguised as a PDF document, such as transcript.pdf.js. Because Windows commonly hides known file extensions, users may only see transcript.pdf, increasing the likelihood of execution through Windows Script Host (WSH). The script launches PowerShell with execution policy bypass arguments, establishing the first stage of the infection chain.<\/p>\n<h3>Stage 2: Blogspot-Based Payload Delivery<\/h3>\n<p>Rather than downloading malware from attacker-owned infrastructure, the PowerShell script retrieves subsequent payloads from attacker-controlled Blogspot pages hosted on Google&#8217;s Blogger platform. Using a trusted cloud service allows outbound traffic to blend with legitimate web activity, potentially reducing the effectiveness of reputation-based URL filtering and domain-blocking controls.<\/p>\n<p>The downloaded script also opens a benign webpage to create the impression that the requested document has loaded successfully while the malicious execution continues in the background.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/From-Detection-to-Defense-The-Evolution-of-Endpoint-Security-in-Modern-Enterprises-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Top 10 security challenges XDR helps address for enterprise teams<\/h4><p>XDR helps enterprises reduce alert fatigue, connect threat signals, and respond faster to complex cyberattacks.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/xdr-security-challenges-enterprise-teams\/\" aria-label=\"Top 10 security challenges XDR helps address for enterprise teams\"><\/a><\/div><\/div><\/div><\/p>\n<h3>Stage 3: Evasion and In-Memory Execution<\/h3>\n<p>After the secondary payload is retrieved, the framework employs multiple evasion techniques to minimize detection and forensic visibility, including:<\/p>\n<ul>\n<li>XOR-obfuscated payloads that are decrypted only at runtime.<\/li>\n<li>Dynamic generation of additional Blogspot URLs to retrieve later-stage components.<\/li>\n<li>Dynamic appending of a random number of forward slashes (\/) to Blogspot URLs, allowing requests to appear unique and helping bypass URL-based filtering and detection mechanisms.<\/li>\n<li>Reflective .NET assembly loading, enabling payloads to execute directly from memory.<\/li>\n<li>Use of Microsoft-signed Living-off-the-Land Binaries (LOLBins) such as RegSvcs, InstallUtil, MSBuild, and aspnet_compiler as fallback execution mechanisms if direct loading is blocked.<\/li>\n<li>Fileless execution, reducing malicious artifacts written to disk and complicating post-compromise forensic analysis.<\/li>\n<\/ul>\n<h3>Stage 4: Final Payload<\/h3>\n<p>The final stage delivers PureLog(s) Stealer, a .NET-based information stealer designed to harvest sensitive data from compromised Windows systems. Reported targets include:<\/p>\n<ul>\n<li>Browser credentials and saved passwords<\/li>\n<li>Session cookies<\/li>\n<li>Autofill data<\/li>\n<li>Cryptocurrency wallet information<\/li>\n<li>Host and system metadata<\/li>\n<\/ul>\n<p>Stolen session cookies can be particularly valuable because they may enable attackers to hijack authenticated sessions without requiring the user&#8217;s password, depending on the target application&#8217;s session management controls.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-1.webp?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity-kit\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-1.webp?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-1-300x225.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-1-768x576.webp?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-1-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity-kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            This resource kit will help your company adopt the right cybersecurity strategy to secure your business.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            DOWNLOAD KIT\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h2>How Hexnode Helps Reduce the Risk<\/h2>\n<p>Campaigns like Veil highlight why organizations need layered endpoint security rather than relying on a single preventive control. By combining endpoint management, endpoint detection and response, and policy enforcement, organizations can reduce the attack surface and respond more quickly when suspicious activity is detected.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\" rel=\"noopener\">Hexnode UEM<\/a> helps strengthen endpoint security by enabling organizations to:<\/p>\n<ul>\n<li>Enforce device compliance policies to ensure endpoints meet organizational security requirements before accessing corporate resources.<\/li>\n<li>Reduce the attack surface through device hardening, timely OS updates, patch management, and approved application policies.<\/li>\n<li>Apply compliance-based access controls so noncompliant devices can be identified and remediated according to organizational policies.<\/li>\n<li>Remotely remediate managed devices, helping IT teams respond quickly when endpoints are suspected of compromise or fall out of compliance.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\" rel=\"noopener\">Hexnode XDR<\/a> complements these controls by providing visibility into endpoint activity that may indicate an attack in progress. Security teams can investigate behaviors such as:<\/p>\n<ul>\n<li>Abnormal PowerShell execution<\/li>\n<li>Suspicious parent-child process relationships<\/li>\n<li>Indicators associated with fileless attack techniques<\/li>\n<li>Potential credential theft activity<\/li>\n<li>Suspicious outbound network connections that may warrant further investigation<\/li>\n<\/ul>\n<p>When malicious activity is confirmed, security teams can respond quickly using Hexnode XDR&#8217;s One-Click Remediation capabilities, including Network Isolation to contain compromised endpoints and Process Kill to terminate malicious processes before they can progress further.<\/p>\n<p>Together, Hexnode UEM and Hexnode XDR help organizations strengthen endpoint resilience by reducing opportunities for compromise, improving visibility into suspicious behavior, and enabling faster investigation and remediation of potentially affected devices.<\/p>\n<h2>Conclusion<\/h2>\n<p>The Veil malware campaign shows how modern attackers are moving beyond traditional delivery techniques. They abuse trusted cloud services, fileless execution, and legitimate system binaries to reduce their detection footprint. For enterprise security teams, the challenge is no longer just blocking known malware. They must also identify malicious behavior that blends into normal administrative activity.<\/p>\n<p>Mitigating these attacks requires a defense-in-depth strategy that combines endpoint hardening, continuous monitoring, policy enforcement, and rapid incident response. Organizations that can detect anomalous script execution, enforce device compliance, and quickly investigate suspicious endpoint activity are better positioned to disrupt multi-stage attack chains before sensitive data is compromised.<\/p>\n<p>As attackers continue to leverage trusted platforms to evade conventional defenses, strengthening endpoint visibility and maintaining proactive security controls remain essential for reducing organizational risk.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Try Hexnode free for 14 days<\/h5><p>Ready to strengthen your endpoint security? Sign in to Hexnode to get started.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign Up Today<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A newly disclosed malware delivery framework known as Veil demonstrates how attackers are combining trusted&#8230;<\/p>\n","protected":false},"author":8,"featured_media":1128,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,15],"class_list":["post-1127","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-malware","product_category-extended-detection-and-response","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Veil Malware: How Attackers Use Blogspot to Deliver Fileless Payloads<\/title>\n<meta name=\"description\" content=\"Learn how the Veil malware campaign uses Blogspot, PowerShell, and fileless techniques\u2014and how enterprises can reduce risk.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/veil-malware-explained\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Veil Malware: How Attackers Use Blogspot to Deliver Fileless Payloads\" \/>\n<meta property=\"og:description\" content=\"Learn how the Veil malware campaign uses Blogspot, PowerShell, and fileless techniques\u2014and how enterprises can reduce risk.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/veil-malware-explained\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-19T14:40:44+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T14:42:01+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Veil-malware.webp?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"535\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Alanna River\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alanna River\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/veil-malware-explained\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/veil-malware-explained\\\/\"},\"author\":{\"name\":\"Alanna River\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\"},\"headline\":\"Veil Malware: How Attackers Use Blogspot to Deliver Fileless Payloads\",\"datePublished\":\"2026-08-19T14:40:44+00:00\",\"dateModified\":\"2026-08-19T14:42:01+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/veil-malware-explained\\\/\"},\"wordCount\":894,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/veil-malware-explained\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Veil-malware.webp?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/veil-malware-explained\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/veil-malware-explained\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/veil-malware-explained\\\/\",\"name\":\"Veil Malware: How Attackers Use Blogspot to Deliver Fileless Payloads\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/veil-malware-explained\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/veil-malware-explained\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Veil-malware.webp?format=webp\",\"datePublished\":\"2026-08-19T14:40:44+00:00\",\"dateModified\":\"2026-08-19T14:42:01+00:00\",\"description\":\"Learn how the Veil malware campaign uses Blogspot, PowerShell, and fileless techniques\u2014and how enterprises can reduce risk.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/veil-malware-explained\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/veil-malware-explained\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/veil-malware-explained\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Veil-malware.webp?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Veil-malware.webp?format=webp\",\"width\":1024,\"height\":535,\"caption\":\"Veil-malware\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/veil-malware-explained\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Veil Malware: How Attackers Use Blogspot to Deliver Fileless Payloads\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\",\"name\":\"Alanna River\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"caption\":\"Alanna River\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/alanna-river\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Veil Malware: How Attackers Use Blogspot to Deliver Fileless Payloads","description":"Learn how the Veil malware campaign uses Blogspot, PowerShell, and fileless techniques\u2014and how enterprises can reduce risk.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/veil-malware-explained\/","og_locale":"en_US","og_type":"article","og_title":"Veil Malware: How Attackers Use Blogspot to Deliver Fileless Payloads","og_description":"Learn how the Veil malware campaign uses Blogspot, PowerShell, and fileless techniques\u2014and how enterprises can reduce risk.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/veil-malware-explained\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-08-19T14:40:44+00:00","article_modified_time":"2026-08-19T14:42:01+00:00","og_image":[{"width":1024,"height":535,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Veil-malware.webp?format=webp","type":"image\/webp"}],"author":"Alanna River","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Alanna River","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/veil-malware-explained\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/veil-malware-explained\/"},"author":{"name":"Alanna River","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64"},"headline":"Veil Malware: How Attackers Use Blogspot to Deliver Fileless Payloads","datePublished":"2026-08-19T14:40:44+00:00","dateModified":"2026-08-19T14:42:01+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/veil-malware-explained\/"},"wordCount":894,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/veil-malware-explained\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Veil-malware.webp?format=webp","articleSection":["Identity Abuse","Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/veil-malware-explained\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/veil-malware-explained\/","url":"https:\/\/www.hexnode.com\/threat-watch\/veil-malware-explained\/","name":"Veil Malware: How Attackers Use Blogspot to Deliver Fileless Payloads","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/veil-malware-explained\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/veil-malware-explained\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Veil-malware.webp?format=webp","datePublished":"2026-08-19T14:40:44+00:00","dateModified":"2026-08-19T14:42:01+00:00","description":"Learn how the Veil malware campaign uses Blogspot, PowerShell, and fileless techniques\u2014and how enterprises can reduce risk.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/veil-malware-explained\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/veil-malware-explained\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/veil-malware-explained\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Veil-malware.webp?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Veil-malware.webp?format=webp","width":1024,"height":535,"caption":"Veil-malware"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/veil-malware-explained\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Veil Malware: How Attackers Use Blogspot to Deliver Fileless Payloads"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64","name":"Alanna River","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","caption":"Alanna River"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/alanna-river\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1127","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1127"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1127\/revisions"}],"predecessor-version":[{"id":1132,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1127\/revisions\/1132"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1128"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1127"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1127"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}