PurpleFox operators have continued to evolve a modular Windows malware platform that combines downloader, backdoor, and botnet capabilities with rootkit-based stealth and persistence. Researchers and CERT-UA linked the threat to campaigns using trojanized MSI and software installers, PowerShell-based fileless chains, WPAD abuse, and exploit-driven propagation, with infections observed from Indonesia and the Middle East to a large outbreak in Ukraine that affected at least 2,000 systems. The malware has also been seen spreading through known vulnerability exploitation and password brute-forcing, while operators rotated through extensive command-and-control infrastructure, including hundreds of intermediate control servers.
Recent PurpleFox activity added a FatalRAT-derived payload and the FoxSocket .NET backdoor, which uses encrypted WebSocket communications for command and control and supports reconnaissance, file theft, process execution, and payload delivery. Trend Micro reported that staged installers disguised as Telegram, WhatsApp, Adobe, and Chrome fetched different second-stage payloads based on filename markers, while signed or revoked code-signing certificates were used to load malicious kernel drivers and disable security tooling such as file system mini-filter drivers. Across multiple campaigns, PurpleFox has exploited vulnerabilities including CVE-2021-1732, CVE-2020-1054, CVE-2019-1367, CVE-2018-8120, and MS15-051, underscoring its shift from exploit-kit delivery to a broader, adaptable intrusion and malware-distribution ecosystem.

Pull IOCs and campaign context straight into your stack.
16 events from the most recent confirmed update back to the earliest known activity.
SentinelLabs analyzed an updated Purple Fox exploit kit campaign that added public exploit code for CVE-2020-1054 and CVE-2019-0808, used steganography to hide privilege-escalation payloads inside image files, and deployed a VMProtect-protected rootkit via MSI installers. The report said the campaign continued targeting vulnerable Internet Explorer users through malicious websites and staged execution with mshta.exe, VBScript, and PowerShell.
CERT-UA warned that PurpleFox had infected more than 2,000 computers in Ukraine and tracked the activity as UAC-0027, publishing indicators and cleanup guidance because the malware is difficult to remove due to its rootkit.
CERT-UA monitored PurpleFox-infected hosts in Ukraine from January 20 through January 31, 2024, identifying 486 intermediate control server IP addresses during the campaign.
Trend Micro reported an updated Purple Fox campaign using trojanized installers masquerading as Telegram, WhatsApp, Adobe, and Chrome to deliver staged payloads, including updated FatalRAT-derived malware and signed rootkit components for evasion.
Trend Micro reported that Purple Fox was targeting Microsoft SQL Server systems for cryptocurrency mining, primarily using malicious .NET CLR Assemblies and T-SQL stored procedures instead of the more heavily monitored xp_cmdshell feature. The report also described a large botnet infrastructure of compromised SQL servers, with more than 1,000 servers observed in just over a week and dynamic DNS activity under kozow[.]com.
Trend Micro identified a new .NET backdoor associated with PurpleFox, named FoxSocket, which used WebSockets for command-and-control and supported encrypted communications, host fingerprinting, and broad remote operations.
Trend Micro Managed XDR investigated suspicious activity related to a PurpleFox operator in September 2021 and found an updated arsenal using PowerShell-based initial access, privilege-escalation exploits, and improved rootkit capabilities.
Trend Micro reported that PurpleFox was being distributed through abuse of the WPAD domain wpad.id, enabling a zero-click infection path that served a JavaScript exploit for CVE-2019-1367 and fetched later stages from related domains.
Trend Micro found older FoxSocket variants dating back to June 22, 2021, noting they had fewer capabilities than later samples.
Trend Micro reported that the domain advb9fyxlf2v[.]com, used by FoxSocket infrastructure for load balancing, was registered on June 17, 2021.
HP isolated a Purple Fox exploit kit sample from a customer in the Middle East on April 12, 2021, and found it attempting to exploit Internet Explorer vulnerability CVE-2021-26411. The report said the exploit closely resembled a public proof of concept released in mid-March 2021, indicating rapid weaponization in the wild.
Proofpoint reported that the Purple Fox exploit kit had expanded its arsenal to include exploits for CVE-2020-0674 and CVE-2019-1458. This documented a new stage in the malware's exploit-kit evolution between the 2019 Rig-based activity and the 2021 exploitation of CVE-2021-26411.
Trend Micro analyzed a new 2019 Purple Fox iteration delivered by the Rig exploit kit that replaced NSIS with PowerShell for fileless infection, added multiple exploit paths, and deployed rootkit-enabled components after reboot.
Trend Micro reported that Purple Fox previously used HTTP File Server infrastructure in 2019 to host files on infected bots. A certificate tied to Hangzhou Hootian Network Technology Co., Ltd. was also strongly connected to this early 2019 activity.
360 Security Center analyzed Purple Fox in a 2018 report, saying the trojan had seriously affected at least 30,000 users. The report detailed its MSI-based delivery, boot persistence via Pending File Rename Operations and sens.dll replacement, and rootkit-style hiding of files and registry entries.
Trend Micro said Purple Fox had been active since at least 2018. Later reporting also described PurpleFox as first spotted in 2018.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 114 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
13 references tracked. Mallory keeps watching after this page renders.
labs.sentinelone.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcetrendmicro.com
Open sourceblog.trendmicro.com
Open sourceblog.360totalsecurity.com
Open sourcetrendmicro.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.