PurpleFox
- Malware type
- rootkit, loader
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:48:14
- Profile updated
- 2026-07-07 14:57:49
Context
Purple Fox uses msi.dll function, 'MsiInstallProductA', to download and execute its payload. The payload is a .msi file that contains encrypted shellcode including 32-bit and 64-bit versions. once executed the system will be restarted and uses the 'PendingFileRenameOperations' registry to rename it's components. Upon restart the rootkit capability of Purple Fox is invoked. It creates a suspended svchost process and injects a DLL that will create a driver with the rootkit capability. The latest version of Purple Fox abuses open-source code to enable it's rootkit components, which includes hiding and protecting its files and registry entries. It also abuses a file utility software to hide its DLL component, which deters reverse engineering.
Detection coverage
- 4 YARA rules
Exploited vulnerabilities
- CVE-2021-26411 (vulnerability)
Detection rules
- SEKOIA_Rootkit_Win_Purplefox_Svchost_Txt (yara-rule)
- SEKOIA_Rootkit_Win_Purplefox_360_Tct (yara-rule)
- SEKOIA_Rootkit_Win_Purplefox_Kernel_Driver (yara-rule)
- MALPEDIA_Win_Purplefox_Auto (yara-rule)
Reports & references
- thehackernews.com — Purple Fox Hackers Spotted Using New (report)
- proofpoint.com — Chinese Malware Appears Earnest Across Cybercrime Threat Landscape (report)
- Trend Micro — Purple Fox Uses New Arrival Vector And Improves Malware Arsenal (report)
- Trend Micro — Purplefox Adds New Backdoor That Uses Websockets (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Purplefox (report)
- threatresearch.ext.hp.com — Purple Fox Exploit Kit Now Exploits Cve 2021 26411 (report)
- Trend Micro — Iocs Purple Fox.Txt (report)
- Trend Micro — Security 101 The Impact Of Cryptocurrency Mining Malware (report)
- thecybersecuritytimes.com — Purple Fox Malware Is Actively Distributed Via Telegram Installers (report)
- s.tencent.com — 1322 (report)
- Trend Micro — Purple Fox Uses New Arrival Vector And Improves Malware Arsenal (report)
- Trend Micro — Purple Fox Fileless Malware With Rookit Component Delivered By Rig Exploit Kit Now Abuses Powershell (report)
- guardicore.com — Purple Fox Rootkit Now Propagates As A Worm (report)
- blogs.blackberry.com — Threat Thursday Purple Fox Rootkit (report)
- Trend Micro — A Look Into Purple Fox Server Infrastructure (report)
- Trend Micro — Technical%20Brief%20 %20A%20Look%20Into%20Purple%20Fox%E2%80%99S%20New%20Arrival%20Vector (report)
- twitter.com — 1412801973628272641 (report)
- blog.minerva-labs.com — Malicious Telegram Installer Drops Purple Fox Rootkit (report)
- blog.malwarebytes.com — Perkiler Malware Turns To Smb Brute Force To Spread (report)
- bleepingcomputer.com — Purplefox Malware Infects Thousands Of Computers In Ukraine (report)
- labs.sentinelone.com — Purple Fox Ek New Cves Steganography And Virtualization Added To Attack Flow (report)
- nao-sec.org — Exploit Kit Still Sharpens A Sword (report)
- Trend Micro — Purplefox Using Wpad To Targent Indonesian Users (report)