PurpleFox

Malware type
rootkit, loader
Family
Malware family
Last IoC activity
2026-07-22 01:48:14
Profile updated
2026-07-07 14:57:49

Context

Purple Fox uses msi.dll function, 'MsiInstallProductA', to download and execute its payload. The payload is a .msi file that contains encrypted shellcode including 32-bit and 64-bit versions. once executed the system will be restarted and uses the 'PendingFileRenameOperations' registry to rename it's components. Upon restart the rootkit capability of Purple Fox is invoked. It creates a suspended svchost process and injects a DLL that will create a driver with the rootkit capability. The latest version of Purple Fox abuses open-source code to enable it's rootkit components, which includes hiding and protecting its files and registry entries. It also abuses a file utility software to hide its DLL component, which deters reverse engineering.

Detection coverage

  • 4 YARA rules

Exploited vulnerabilities

  • CVE-2021-26411 (vulnerability)

Detection rules

  • SEKOIA_Rootkit_Win_Purplefox_Svchost_Txt (yara-rule)
  • SEKOIA_Rootkit_Win_Purplefox_360_Tct (yara-rule)
  • SEKOIA_Rootkit_Win_Purplefox_Kernel_Driver (yara-rule)
  • MALPEDIA_Win_Purplefox_Auto (yara-rule)

Reports & references

  • thehackernews.com — Purple Fox Hackers Spotted Using New (report)
  • proofpoint.com — Chinese Malware Appears Earnest Across Cybercrime Threat Landscape (report)
  • Trend Micro — Purple Fox Uses New Arrival Vector And Improves Malware Arsenal (report)
  • Trend Micro — Purplefox Adds New Backdoor That Uses Websockets (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Purplefox (report)
  • threatresearch.ext.hp.com — Purple Fox Exploit Kit Now Exploits Cve 2021 26411 (report)
  • Trend Micro — Iocs Purple Fox.Txt (report)
  • Trend Micro — Security 101 The Impact Of Cryptocurrency Mining Malware (report)
  • thecybersecuritytimes.com — Purple Fox Malware Is Actively Distributed Via Telegram Installers (report)
  • s.tencent.com — 1322 (report)
  • Trend Micro — Purple Fox Uses New Arrival Vector And Improves Malware Arsenal (report)
  • Trend Micro — Purple Fox Fileless Malware With Rookit Component Delivered By Rig Exploit Kit Now Abuses Powershell (report)
  • guardicore.com — Purple Fox Rootkit Now Propagates As A Worm (report)
  • blogs.blackberry.com — Threat Thursday Purple Fox Rootkit (report)
  • Trend Micro — A Look Into Purple Fox Server Infrastructure (report)
  • Trend Micro — Technical%20Brief%20 %20A%20Look%20Into%20Purple%20Fox%E2%80%99S%20New%20Arrival%20Vector (report)
  • twitter.com — 1412801973628272641 (report)
  • blog.minerva-labs.com — Malicious Telegram Installer Drops Purple Fox Rootkit (report)
  • blog.malwarebytes.com — Perkiler Malware Turns To Smb Brute Force To Spread (report)
  • bleepingcomputer.com — Purplefox Malware Infects Thousands Of Computers In Ukraine (report)
  • labs.sentinelone.com — Purple Fox Ek New Cves Steganography And Virtualization Added To Attack Flow (report)
  • nao-sec.org — Exploit Kit Still Sharpens A Sword (report)
  • Trend Micro — Purplefox Using Wpad To Targent Indonesian Users (report)

External references