PurpleUrchin is a financially motivated cloud-abuse threat actor associated with large-scale freejacking operations. The actor is known for systematically creating and cultivating fraudulent online accounts and personas to obtain access to free-tier or trial-based cloud and developer services, then monetizing those resources for cryptocurrency mining. PurpleUrchin has been referenced as a notable example of how low direct attacker profit can impose disproportionately high infrastructure costs on service providers. The actor’s tradecraft centers on account establishment and infrastructure acquisition rather than traditional intrusion against enterprise networks. Reported behavior includes automating the creation of trial accounts, using fabricated or disposable identity elements to pass registration workflows, and abusing free compute offerings on platforms such as Google Cloud Vertex AI through Jupyter Notebook environments. PurpleUrchin-linked activity has involved provisioning multiple GPU-capable notebook instances across regions and deploying cryptominers to consume the allotted trial resources until expiration. Observed tactics and capabilities include initial access through fraudulent account creation, abuse of free services to acquire infrastructure, operational scaling through automation, and post-access execution of cryptocurrency mining workloads. The actor also aligns with broader adversary patterns of persona development and account cultivation across online platforms to support malicious operations. PurpleUrchin is best characterized as a cloud-resource abuse and crypto-mining actor rather than a ransomware or espionage group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a prior example/case study of freejacking economics (small attacker profit causing disproportionate provider loss). No additional operational details are provided in this content.
Referenced in the context of abusing free services and trial registrations to acquire infrastructure for malicious use.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.