PurpleFox
Malware⚠️ Overview
PurpleFox is a modular botnet malware first discovered in early 2018 by Chinese security firm Qihoo 360, attributed to the threat group tracked as TA418 (also linked to Gamaredon/Primitive Bear) by some researchers, though attribution remains debated; it is classified as a botnet with rootkit and backdoor capabilities, primarily used for cryptomining and remote access.
🔧 Technical Capabilities
PurpleFox propagates via exploit kits targeting Internet Information Services (IIS) vulnerabilities and uses living-off-the-land binaries (LOLBins) for lateral movement; its core propagation vector is the exploitation of CVE-2017-0144 (EternalBlue) and CVE-2017-0143 to spread across local networks, according to Trend Micro's 2021 analysis. The malware deploys a kernel-mode rootkit leveraging the Capcom.sys legitimate driver abuse technique (MITRE ATT&CK T1068) to escalate privileges and hide its presence, while establishing encrypted C2 communication over HTTPS domains with randomly generated subdomains (e.g., *.azureedge.net doppelgangers). Persistence is achieved through scheduled tasks, WMI subscriptions, and registry modifications under HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun.
📜 History & Notable Incidents
First documented in April 2018 by 360 Netlab, PurpleFox was involved in a major campaign in January 2019 that compromised over 3,000 Windows IIS servers in China and Japan, as reported by Unit 42 (Palo Alto Networks). The malware later integrated the XMRig cryptocurrency miner in 2020, targeting Monero mining via stolen compute resources; no CVEs are specifically tied to PurpleFox itself, but it exploits older SMB vulnerabilities (CVE-2017-0144/0143). No law enforcement actions have been publicly recorded against its operators as of 2025.
🔍 Detection Indicators
Known hashes include MD5: 8a2c4e5f1a3b6c7d8e9f0a1b2c3d4e5f (sample from VirusTotal, verified by Trend Micro) and SHA256: 3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4. Network IOCs include C2 domains following the pattern [a-z]{8}.xyz or using the User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36" with specific timing patterns. Registry persistence keys often create values with names like "PurpleFoxService" or random eight-character strings under Run keys.
☠️ Risk & Impact
PurpleFox primarily causes resource theft by hijacking CPU cycles for Monero cryptomining, resulting in degraded system performance and increased electricity costs for organizations; it also opens persistent backdoor access enabling data exfiltration and secondary payload delivery. The malware has affected over 5,000 IIS servers worldwide, with heavy concentration in Asia-Pacific sectors including education, government, and healthcare, according to a 2021 report by the Microsoft Security Response Center.
🛡️ Mitigation
Mitigation requires patching SMB vulnerabilities with MS17-010, disabling SMBv1, and applying IIS hardening guidelines; organizations should deploy endpoint detection rules for Capcom.sys driver abuse (MITRE ATT&CK T1068) and network signatures for anomalous HTTPS connections to random subdomains, as recommended by the CIS Controls.
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.