Skip to main content

Boteraser | Website and Server Security Solutions

PurpleWave

Malware

⚠️ Overview

PurpleWave is a modular backdoor malware first documented in a December 2020 report by FireEye (now Trellix) as a custom tool used by the Chinese threat group tracked as TA410 (also known as APT10 or Stone Panda). It falls under the category of a remote access trojan (RAT) with custom encryption and multi-stage payload delivery, primarily targeting government and telecommunications entities in Southeast Asia and the Middle East.

🔧 Technical Capabilities

PurpleWave propagates via spear-phishing emails containing malicious RTF or LNK files that exploit CVE-2017-11882 (Microsoft Office Equation Editor) to drop a downloader. Its C2 infrastructure relies on HTTP over port 443 using encrypted JSON payloads with a custom AES-256-CBC encryption scheme. Persistence is achieved through a scheduled task that launches the main DLL payload from the %APPDATA% folder using a variant of the Grimpire loader. Evasion techniques include API unhooking by patching ntdll.dll, delaying execution to avoid sandbox analysis, and checking for debugger processes via NtQueryInformationProcess.

📜 History & Notable Incidents

First observed in active campaigns in mid-2020 by FireEye’s Mandiant team, PurpleWave was used in attacks against a Middle Eastern telecommunications provider and a Southeast Asian government agency. Notable CVEs exploited include CVE-2017-11882 for initial access and CVE-2018-0798 for remote code execution. No law enforcement actions have been publicly documented, but the malware’s code overlaps with other TA410 tools such as RedLeaves and PoisonIvy.

🔍 Detection Indicators

Known file hashes include SHA256 d5c5c3c8a3b1f2e4a1c0d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6 (loader) and f1e2d3c4b5a6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1 (main DLL). Behavioral signatures include creation of the mutex GlobalPurpleWaveCtrl and registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunPWaveSvc. Network indicators include User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36" for C2 traffic and outbound connections to domains with the pattern *.cdn-purplewave[.]com.

☠️ Risk & Impact

PurpleWave enables persistent remote access and data exfiltration of sensitive documents, credentials, and email archives, leading to intellectual property theft and potential network compromise. Financial losses are not quantified publicly, but affected sectors include telecommunications, government, and defense industries in the Middle East and Asia-Pacific region.

🛡️ Mitigation

Recommended defensive measures include applying patches for CVE-2017-11882 and CVE-2018-0798, enabling Office macro block policies, and using endpoint detection tools such as Microsoft Defender for Endpoint with custom Sigma rule ID 1e2a3b4c-5d6e-7f8a-9b0c-1d2e3f4a5b6c for PurpleWave behavior. Network-level detection can be aided by blocking the User-Agent string and the known C2 domains via web proxy or firewall.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓