Purple Fox is malware active since at least 2018 and historically associated with delivery via the Purple Fox Exploit Kit. The provided reporting shows it being delivered in multiple 2023 email campaigns using Chinese-language business lures, especially invoice-themed messages, as well as at least one Japanese-language invoice-themed campaign. Delivery methods included URLs in emails leading to compressed executables and zipped LNK attachments that resulted in Purple Fox installation. Proofpoint assessed these campaigns as part of broader 'Chinese-themed' malware activity primarily targeting Chinese-language speakers at global organizations with operations in China, while at least one campaign targeted organizations in Japan.
Purple Fox also appeared in a separate intrusion chain documented by Kaspersky in which Prometei operators brute-forced MS SQL credentials, abused xp_cmdshell, exploited CVE-2016-0099 for privilege escalation, and then installed both the Purple Fox Trojan and the Prometei backdoor on victim machines. Kaspersky stated this chain from SQL credential brute-forcing through malware installation was fully automated. In the supplied content, Purple Fox is additionally mentioned alongside Sainbox RAT and ValleyRAT in campaigns targeting Chinese-speaking Windows users that researchers linked to Silver Fox (also known as Void Arachne), although the content does not attribute all Purple Fox activity to a single actor.
High-confidence characteristics from the content are that Purple Fox is a Trojan malware family, available since at least 2018, used in email-borne campaigns and in automated post-exploitation deployment by Prometei. The content does not provide specific Purple Fox command-and-control indicators or detailed internal capabilities beyond its installation as a Trojan payload in these campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Having thus obtained usernames and passwords for computers with MS SQL installed, the attackers used the T-SQL function xp_cmdshell to run several PowerShell scripts and elevated the privileges of the current user by exploiting the CVE-2016-0099 vulnerability. | After that, Purple Fox Trojan and Prometei itself were installed on the victim’s machine.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
“Since early 2023, Proofpoint observed an increase in the email distribution of malware… The email subjects and content are usually written in Chinese… related to business themes like invoices, payments, and new products.”
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware mentioned as being distributed alongside Sainbox RAT and ValleyRAT in campaigns targeting Chinese-speaking users. Specific functionality not detailed in this content.
Malware family observed delivered via multiple methods (historically via Purple Fox Exploit Kit; also masquerading as legitimate installers). In this reporting, delivered via Chinese- and Japanese-language invoice-themed lures, including zipped LNK attachments or URLs leading to payload installation.
A trojan installed during the Prometei infection chain after exploitation of CVE-2016-0099.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.