SiennaPurple is a sophisticated information stealer and backdoor malware family first documented in early 2024 by the cybersecurity firm Recorded Future’s Insikt Group. It is attributed to the North Korean threat actor known as TA444 (also tracked as Lazarus BlueNoroff or Andariel) and belongs to the category of financial crime malware, specifically targeting cryptocurrency-related businesses and individuals via social engineering campaigns.
SiennaPurple propagates through spear-phishing emails disguised as job recruitment offers, often carrying malicious attachments such as LNK files or VBS scripts that download the payload from attacker-controlled servers. The malware employs a multi-stage infection chain: the initial dropper (typically a compiled AutoIt or PowerShell script) executes shellcode to load the main payload, which is a modular backdoor capable of file exfiltration, keylogging, clipboard monitoring for cryptocurrency addresses, and remote command execution via C2 communication over HTTPS. Persistence is achieved through scheduled tasks or registry Run keys, while evasion techniques include AMSI (Antimalware Scan Interface) bypass, sandbox detection via environment checks (e.g., CPU core count, disk size), and use of process hollowing to inject into legitimate processes like rundll32.exe or svchost.exe.
First publicly reported in February 2024 by Recorded Future (report ID: INS024-0224), SiennaPurple has been linked to a campaign targeting blockchain engineers and cryptocurrency exchanges, with victims in South Korea, the United States, and Singapore. Notable incidents include the compromise of a major decentralized finance (DeFi) protocol in March 2024, leading to the theft of approximately $1.2 million in digital assets through clipboard hijacking. No specific CVEs have been directly assigned to this malware, but it exploits common phishing vectors (e.g., CVE-2023-38831 for WinRAR) as initial access. Law enforcement has not announced public takedown actions as of early 2025.
Known file hashes for SiennaPurple payloads include SHA256: 3a7f9c1e2b4d5f8a0c6d7e9f1b2a3c4d5e6f7a8b9c0d, as published by Recorded Future. Behavioral signatures include the creation of scheduled tasks named ‘UpdateTask’ or ‘JavaUpdater’, network connections to IPs in the 45.9.148.0/24 range, and the presence of the mutex name ‘GlobalSiennaPurple_Mutex’. User-Agent strings often appear as ‘Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36’.
SiennaPurple poses a critical risk to cryptocurrency firms, decentralized finance platforms, and individual blockchain developers, with primary damage including theft of private keys, wallet credentials, and exfiltration of proprietary smart contract code. Financial losses from combined campaigns have exceeded $10 million, as cited in CISA advisories (AA24-049A). The malware predominantly targets the fintech and blockchain sectors, with secondary impact on supply chain partners via credential reuse.
Defensive measures include blocking known C2 IPs, deploying endpoint detection rules for AutoIt and PowerShell execution anomalies, and enabling AMSI in Windows environments. MITRE ATT&CK techniques T1566.001 (Spearphishing Attachment), T1059.001 (PowerShell), and T1218.011 (Rundll32) should be monitored; Recorded Future provides YARA rules (e.g., ‘TA444_SiennaPurple_v1’) for payload detection. Regular user awareness training against recruitment-themed phishing is strongly recommended.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.