Purple Fox is a multi-component Windows malware family active since at least 2018 that has evolved from a trojan delivered by exploit kits into a modular botnet and malware delivery platform with rootkit, loader, downloader, remote-access, and cryptocurrency-mining functionality. It has been associated with exploit-kit activity, trojanized software installers, SQL Server intrusions, and follow-on deployment of additional malware families including miners and FatalRAT-derived implants.
Purple Fox was initially observed being delivered through the Rig exploit kit and later through its own exploit framework targeting vulnerable Internet Explorer environments. Documented infection chains used browser exploitation and staged PowerShell execution, including exploitation of vulnerabilities such as CVE-2020-0674, CVE-2019-1458, CVE-2021-26411, CVE-2020-1054, CVE-2019-0808, CVE-2015-1701, CVE-2018-8120, CVE-2018-15982, and CVE-2014-6332. Campaigns also used search-engine redirection, malicious websites, geofencing, steganography to conceal scripts or privilege-escalation components inside image files, and MSI-based payload deployment. Later activity expanded distribution to trojanized installers masquerading as popular software, including messaging, browser, and productivity applications, to infect users directly and grow botnet infrastructure. Email-delivered campaigns using Chinese- and Japanese-language business lures have also been linked to Purple Fox delivery.
On compromised systems, Purple Fox commonly uses staged loaders and shellcode to execute payloads in memory, including creation of suspended processes and injection into svchost. MSI packages have contained encrypted shellcode, architecture-specific DLL payloads, and non-PE encrypted components. Purple Fox has repeatedly used the Windows PendingFileRenameOperations mechanism to replace protected system components and achieve persistence across reboot. Some variants restore original files after execution to reduce visibility while retaining persistence and follow-on execution paths.
A defining feature of Purple Fox is its kernel-mode rootkit capability. Reported variants deploy malicious or signed kernel drivers and user-mode clients that communicate through IOCTLs. The rootkit has been used to hide files, directories, registry keys, and registry values; block access to protected artifacts; erase or reduce visibility of driver information; and intercept filesystem operations for defense evasion. More recent variants have included functionality to enumerate and unregister file-system mini-filter drivers used by security products, as well as kill or disrupt security processes. Customized signed drivers and abuse of stolen or revoked code-signing certificates have been observed as part of these evasion efforts.
Purple Fox has also been used as a botnet and malware deployment framework. Operators have delivered additional software after initial compromise, including cryptocurrency miners and FatalRAT-derived backdoors. FatalRAT-related components associated with Purple Fox can execute commands, fingerprint victim systems, exfiltrate sensitive data, and load auxiliary modules conditionally based on host characteristics such as installed security software. Code and operational overlaps with Zegost have also been reported.
Separate Purple Fox activity has targeted Microsoft SQL Server systems, especially for cryptocurrency mining. In these intrusions, operators favored servers for their compute resources and used brute-force attacks and SQL Server CLR assemblies to execute malicious code from within the database environment, avoiding more heavily monitored mechanisms. Purple Fox infrastructure in these campaigns has been described as a large botnet of compromised servers, and the broader operational objective has frequently included Monero mining.
Purple Fox remains under active development and is notable for rapid adoption of public exploit code, modular staging, strong emphasis on privilege escalation and defense evasion, and flexible use as both an intrusion enabler and a payload delivery ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Purple Fox fileless downloader malware... Also delivered by the Rig exploit kit... It now also eschews its use of NSIS in favor of abusing PowerShell, making Purple Fox capable of fileless infection.
The Purple Fox fileless downloader malware... Also delivered by the Rig exploit kit... It now also eschews its use of NSIS in favor of abusing PowerShell, making Purple Fox capable of fileless infection.
The Purple Fox fileless downloader malware... Also delivered by the Rig exploit kit... It now also eschews its use of NSIS in favor of abusing PowerShell, making Purple Fox capable of fileless infection.
The Purple Fox fileless downloader malware... Also delivered by the Rig exploit kit... It now also eschews its use of NSIS in favor of abusing PowerShell, making Purple Fox capable of fileless infection.
The Purple Fox fileless downloader malware... Also delivered by the Rig exploit kit... It now also eschews its use of NSIS in favor of abusing PowerShell, making Purple Fox capable of fileless infection.
On 12 April 2021, we isolated a Purple Fox EK sample... the sample attempted to exploit a memory corruption vulnerability in Internet Explorer (CVE-2021-26411)... Other Purple Fox EK samples exploiting this vulnerability in the wild were also reported... | Purple Fox is a multi-component malware family that was first documented by Qihoo 360 in September 2018. Originally, it was a trojan that was delivered using the Rig exploit kit (EK). Since then its developers have added new capabilities, including a rootkit component and an exploit kit (also known as Purple Fox EK) to deliver the malware.
Our investigations reveal that Purple Fox has iterated to include use of two recent CVEs – CVE-2020-1054 and CVE-2019-0808 – through publicly-available exploit code... Further, two new exploits are now being utilized to help with local privilege escalation: CVE-2020-1054 and CVE-2019-0808. Both are kernel exploits in the Win32k component. | In recent weeks, we have seen a spike in the number of attempts to attack vulnerable versions of Internet Explorer by actors leveraging the Purple Fox exploit kit.
Exploits against two vulnerabilities, CVE-2020-0674 and CVE-2019-1458, were integrated into Purple Fox at this time. The former exploits a vulnerability in Internet Explorer’s scripting engine to gain code execution... | Purple Fox is a multi-component malware family that was first documented by Qihoo 360 in September 2018. Originally, it was a trojan that was delivered using the Rig exploit kit (EK). Since then its developers have added new capabilities, including a rootkit component and an exploit kit (also known as Purple Fox EK) to deliver the malware.
PowerShell scripts are extracted from the downloaded images, which are then executed and lead to privilege escalation through one of the integrated exploits: CVE-2015-1701 CVE-2018-8120 CVE-2019-1458 CVE-2019-0808 CVE-2020-1054 CVE-2021-1732 (Nb. The exploit delivered by Purple Fox EK is similar to this publicly available PoC.) | Purple Fox is a multi-component malware family that was first documented by Qihoo 360 in September 2018. Originally, it was a trojan that was delivered using the Rig exploit kit (EK). Since then its developers have added new capabilities, including a rootkit component and an exploit kit (also known as Purple Fox EK) to deliver the malware.
Our investigations reveal that Purple Fox has iterated to include use of two recent CVEs – CVE-2020-1054 and CVE-2019-0808 – through publicly-available exploit code... Further, two new exploits are now being utilized to help with local privilege escalation: CVE-2020-1054 and CVE-2019-0808. Both are kernel exploits in the Win32k component. | In recent weeks, we have seen a spike in the number of attempts to attack vulnerable versions of Internet Explorer by actors leveraging the Purple Fox exploit kit.
Exploits against two vulnerabilities, CVE-2020-0674 and CVE-2019-1458, were integrated into Purple Fox at this time... the latter exploits a vulnerability in win32k.sys to run code with elevated privileges. | Purple Fox is a multi-component malware family that was first documented by Qihoo 360 in September 2018. Originally, it was a trojan that was delivered using the Rig exploit kit (EK). Since then its developers have added new capabilities, including a rootkit component and an exploit kit (also known as Purple Fox EK) to deliver the malware.
Having thus obtained usernames and passwords for computers with MS SQL installed, the attackers used the T-SQL function xp_cmdshell to run several PowerShell scripts and elevated the privileges of the current user by exploiting the CVE-2016-0099 vulnerability. | After that, Purple Fox Trojan and Prometei itself were installed on the victim’s machine.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
The exploit runs mshta.exe with VBScript code as a command line, which then runs PowerShell. The PowerShell code downloads and executes in memory the next stage of code
Installation command behavior: /c start “” “C:WindowsTEMPFastpic_u44047309_sv67_52_1.exe” /at=591 /tid1=67
The exploit runs mshta.exe with VBScript code as a command line, which then runs PowerShell.
Our investigations reveal that Purple Fox has iterated to include use of two recent CVEs – CVE-2020-1054 and CVE-2019-0808 – through publicly-available exploit code.
It is worth noting that all of the scripts check for a specific and consistent registry value named “StayOnTop” under HKCUSoftware7-Zip. It appears that setting this value enables the malware to determine if the payload ran successfully.
if it decrypts the memory DLL and driver files, create the Svchost process and inject the Shellcode to execute, and then write the DLL and driver remotely into the Svchost process
Register the MiniFilter and thread callback at the driver entry... Hide its own Trojan files in MiniFilter... The 32-bit hook NtEnumerateKey function hides its own registry entries... Then replace the NtfsFsdCreate dispatch function of Ntfs.sys
Examining the exploit code shows that it is obfuscated in several stages and encrypted using AES.
Notably, malicious code is hidden inside the images using steganography to avoid detection by web proxies and firewalls.
We still see the use of PendingFileRenameOperations for placing the files under the system32 directory after a reboot. | In the past, Purple Fox would download local privilege escalation (LPE) binaries that used an image file extension ( update.jpg) but which was in fact a regular executable file.
if it decrypts the memory DLL and driver files, create the Svchost process and inject the Shellcode to execute, and then write the DLL and driver remotely into the Svchost process
Following this, copy the DLL code to the temporary memory, then free the DLL, and then write the temporary memory back to the process code to hide and delete the Trojan DLL... Erase the driver information
Then decrypt the non-PE and create a service start
The script checks whether the user is an administrator and installs the malware using an MSI file if this is the case.
The 32-bit hook NtEnumerateKey function hides its own registry entries | Hide its own Trojan files in MiniFilter
The C&C servers used in the communication schemes that have been described here are infected servers that are part of the botnet used to host the various payloads for Purple Fox.
After starting the downloader, the Trojan installation package download address will be downloaded online
Both initial DNS requests are CNAMEs to subdomains under kozow[.]com, which is a free dynamic domain service provided by dynu[.]com. This service can be updated with an API to make it point to different IP addresses — a technique the attacker uses to change the IP address at a regular interval.
93 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware mentioned as being distributed alongside Sainbox RAT and ValleyRAT in campaigns targeting Chinese-speaking users. Specific functionality not detailed in this content.
Purple Fox is an actively developed exploit kit and malware/rootkit delivery framework targeting vulnerable Internet Explorer systems. In this report it uses PowerShell-based fileless execution, steganography to hide local privilege escalation payloads, and VMProtect-obfuscated rootkit installers to gain elevated access and install a rootkit.
Malware family observed delivered via multiple methods (historically via Purple Fox Exploit Kit; also masquerading as legitimate installers). In this reporting, delivered via Chinese- and Japanese-language invoice-themed lures, including zipped LNK attachments or URLs leading to payload installation.
Purple Fox is malware/botnet infrastructure that uses trojanized software installers as an infection vector, deploys second-stage payloads from remote servers, and includes a rootkit module with kernel-level file copy/delete capabilities and antivirus evasion via intercepted file system calls.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.