DirtyMoe is a modular Windows malware family primarily associated with cryptojacking and distributed denial-of-service activity. It has been linked to earlier activity under the name NuggetPhantom and is frequently distributed through the Purple Fox ecosystem, including exploit-driven MSI-based installation chains and trojanized software installers. Additional observed delivery methods include phishing, malvertising, repacked installers, cracks, and keygens.
DirtyMoe is designed to obtain high privileges and establish durable persistence on compromised systems. Its installation workflow abuses Windows Installer packages to prepare the host, weaken defenses, and replace legitimate service components so that malicious code executes as a trusted Windows service with SYSTEM privileges after reboot. On infected hosts it commonly operates through service-based components that launch core worker processes responsible for downloading, decrypting, and injecting modular payloads into memory.
A notable component of DirtyMoe is a kernel-mode driver that functions as a rootkit and privileged support backdoor for user-mode modules. This driver can hide files, registry keys, services, and loaded drivers; intercept filesystem activity; restrict access for selected processes; and assist user-mode malware with privileged operations such as process termination, registry modification, and writing into protected locations. It also supports DLL injection into newly created processes and has been observed using signed drivers and anti-forensic measures to reduce visibility.
DirtyMoe includes worm-like propagation modules that enable spread without further user interaction after initial compromise. Observed propagation methods include exploitation of SMB vulnerabilities such as EternalBlue, use of local privilege-escalation exploits, brute-force and dictionary attacks against remote management and database services, and lateral movement across local subnets and broader internet address space. The malware can reuse harvested credentials to improve propagation efficiency and has shown the ability to target both public-facing and internal systems.
The malware uses encrypted modular payloads, anti-debugging and anti-tracking techniques, process protection through mutually guarded workers, and obfuscation to complicate analysis and detection. Its command-and-control design supports retrieval of additional modules and operational updates, while its modular architecture allows operators to combine mining, propagation, rootkit, and other post-compromise functions as needed. DirtyMoe has been observed at scale for years and is assessed as an actively maintained Windows threat with botnet, mining, and stealth capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
PHP CVE:2019-9082: ThinkPHP - Multiple PHP Injection RCEs. The module uses the exact implementation published at [7]. In short, a CGI script that verifies the ability of call_user_func_array is sent. If the verification is passed, the CGI script is re-sent with @RCE@. | The DirtyMoe malware is deployed using various kits like PurpleFox or injected installers of Telegram Messenger that require user interaction. Complementary to this deployment, one of the DirtyMoe modules expands the malware using worm-like techniques that require no user interaction.
The analysis showed that the worming module targets older well-known vulnerabilities, e.g., EternalBlue and Hot Potato Windows Privilege Escalation... The DirtyMoe worm abuses several known vulnerabilities as follow: CVE:2017-0144 : EternalBlue SMB Remote Code Execution (MS17-010)... One of the main vulnerabilities is CVE:2017-0144 : EternalBlue SMB Remote Code Execution. | The DirtyMoe malware is deployed using various kits like PurpleFox or injected installers of Telegram Messenger that require user interaction. Complementary to this deployment, one of the DirtyMoe modules expands the malware using worm-like techniques that require no user interaction.
However, we list a shortlist of used CVE for DirtyMoe as follows: CVE-2019-1458 , CVE-2015-1701 , CVE-2018-8120 : Win32k Elevation of Privilege Vulnerability | This article presents the result of our recent research on the DirtyMoe malware. We noticed that the NuggetPhantom malware had been the first version of DirtyMoe, and PurpleFox is its exploit kit.
However, we list a shortlist of used CVE for DirtyMoe as follows: CVE-2019-1458 , CVE-2015-1701 , CVE-2018-8120 : Win32k Elevation of Privilege Vulnerability | This article presents the result of our recent research on the DirtyMoe malware. We noticed that the NuggetPhantom malware had been the first version of DirtyMoe, and PurpleFox is its exploit kit.
CVE-2014-6332 : Windows OLE Automation Array Remote Code Execution Vulnerability | This article presents the result of our recent research on the DirtyMoe malware. We noticed that the NuggetPhantom malware had been the first version of DirtyMoe, and PurpleFox is its exploit kit.
CVE:2018-0147 : Deserialization Vulnerability... Deserialization CVE:2018-0147: Deserialization Vulnerability The current module implementation executes a malicious Java class on an attacked server. | The DirtyMoe malware is deployed using various kits like PurpleFox or injected installers of Telegram Messenger that require user interaction. Complementary to this deployment, one of the DirtyMoe modules expands the malware using worm-like techniques that require no user interaction.
Another way to infect a victim machine with DirtyMoe is phishing emails containing URLs that can exploit targets via Internet Explorer; for instance, the Scripting Engine Memory Corruption Vulnerability ( CVE-2020-0674 ). | This article presents the result of our recent research on the DirtyMoe malware. We noticed that the NuggetPhantom malware had been the first version of DirtyMoe, and PurpleFox is its exploit kit.
The DirtyMoe worm abuses several known vulnerabilities as follow: CVE:2019-1458 : WizardOpium Local Privilege Escalation... the malware authors utilize... CVE-2019-1458 : 'WizardOpium Local Privilege Escalation' exploit. | The DirtyMoe malware is deployed using various kits like PurpleFox or injected installers of Telegram Messenger that require user interaction. Complementary to this deployment, one of the DirtyMoe modules expands the malware using worm-like techniques that require no user interaction.
CVE:2019-2725 : Oracle Weblogic Server – ‘AsyncResponseService’ Deserialization RCE... Oracle Weblogic Server CVE:2019-2725: Oracle Weblogic Server - 'AsyncResponseService' Deserialization RCE... The module again exploits vulnerabilities published at [9] to send malicious SOAP payloads without any authentication to the Oracle Weblogic Server T3 interface. | The DirtyMoe malware is deployed using various kits like PurpleFox or injected installers of Telegram Messenger that require user interaction. Complementary to this deployment, one of the DirtyMoe modules expands the malware using worm-like techniques that require no user interaction.
41 distinct techniques documented for this family, organized by ATT&CK tactic.
The most common way of deploying the DirtyMoe malware is via phishing campaigns or malvertising.
sp_start_job The module creates, schedules, and immediately runs a task with Payload 1
xp_cmdshell This method spawns a Windows command shell and passes in a string for execution represented by Payload 3
The malware is written using Delphi in most cases. Naturally, the driver is coded in native C.
Further, a wide range of infected files is a way to deploy DirtyMoe. Crack, Keygen, but even legit-looking applications could consist of malicious code that installs malware into victim machines as a part of their execution process. | Infected macros, self-extracting archive, and repacked installers of popular applications are the typical groups.
sp_start_job The module creates, schedules, and immediately runs a task with Payload 1
The module stores all previously successful passwords in the system registry; the first phase of the dictionary attack iterates through all stored passwords
DirtyMoe is run as a Windows service under system-level privileges... The infected SENS Service registers the DirtyMoe Service in the system as a regular Windows service. Consequently, the DirtyMoe malware can survive the system reboot.
sp_start_job The module creates, schedules, and immediately runs a task with Payload 1
The worming module is then decrypted and injected into a new svchost.exe process
The x64 OS version abuses the original NtTestAlert() routine, which checks the thread’s APC queue. The APC (Asynchronous Procedure Call) is a technique to queue a job to be done in the context of a specific thread.
the malware authors utilize the MS15-076 implementation known as Tater, the PowerSploit function Invoke-ReflectivePEInjection, and CVE-2019-1458 : “WizardOpium Local Privilege Escalation” exploit.
DirtyMoe is run as a Windows service under system-level privileges... The infected SENS Service registers the DirtyMoe Service in the system as a regular Windows service. Consequently, the DirtyMoe malware can survive the system reboot.
It extracts a Windows driver that utilizes various rootkit capabilities such as service, registry entry, and driver hiding. Additionally, the driver can hide selected files on the system volume and can inject an arbitrary DLL into each newly created process in the system.
The workers are initially run as svchost.exe , but the DirtyMoe driver changes the worker’s process names to fontdrvhost.exe .
The worming module is then decrypted and injected into a new svchost.exe process
The x64 OS version abuses the original NtTestAlert() routine, which checks the thread’s APC queue. The APC (Asynchronous Procedure Call) is a technique to queue a job to be done in the context of a specific thread.
The loaded driver also removes the dumped ( dump_ prefix) driver file.
When the driver is loaded, the DirtyMoe service deletes all registry entries related to the driver loading.
ImagePath: %SystemRoot%\system32\svchost.exe -k netsvcs | DirtyMoe drivers are signed with three certificates... Although all certificates have been revoked in the past, Windows loads these drivers successfully because the root certificate authorities are marked as trusted.
The Microsoft HTML Application Host ( mshta.exe ) is used as a LOLbin to execute and create ShellWindows and run @RCE@ .
The core of the @RCE@ command is the execution of the remote DirtyMoe object ( http:// ) via msiexec in silent mode ( /Q ).
The driver provides key functionalities to hide malicious processes, services, and registry keys.
The FltPostOperation() method can modify a result of the QueryDirectory operations (IRP). In fact, the malware driver can affect (hide, insert, modify) a directory enumeration.
The driver can hide a given registry key... the driver can filter which registry keys will be visible; more precisely, which keys will be searched in the hash table.
The MSI package overwrites the system file sens.dll via the Windows Session Manager. Therefore, DirtyMoe abuses the Windows System Event Notification (SENS) to be started by the system.
The payload delivery is typically performed using protocols of targeted services, e.g., SMB or MS SQL protocols.
The payload delivery is typically performed using protocols of targeted services, e.g., SMB or MS SQL protocols.
DirtyMoe makes a DNS request to one hard-coded domain using a set of hardcoded DNS servers. However, the final IP address and port are derived using another sequence of DNS requests.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DirtyMoe is another botnet that Purple Fox was used to deploy in a separate campaign mentioned for context.
Modular malware whose primary function is crypto-mining, with worming modules that spread via exploit-based propagation, dictionary attacks against SCMR/WMI/MS SQL, and lateral movement across public and local networks.
DirtyMoe is deployed via MSI installer packages that modify registry settings, disable protections, replace protected Windows service DLLs such as sens.dll or cscdll.dll after reboot, and execute as a legitimate SYSTEM service for persistence and stealth.
DirtyMoe is a modular malware family used for cryptojacking and DDoS attacks. In this reference, it is described as deploying a signed Windows kernel driver/rootkit that hides files, registry keys, services, and drivers; patches services.exe; filters filesystem access via a minifilter; injects arbitrary DLLs into newly created processes/threads; and removes forensic evidence of its own loading from disk and registry.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.