2021-12-30

Purple Fox Rootkit

Level: 
Tactical
  |  Source: 
Minerva-Labs
Information & Technology
Share:

Purple Fox Rootkit

Research from Minerva reports MalwareHunterTeam, identified a malicious Telegram installer compiled in AutoIt, named "Telegram Desktop.exe.” Resulting in infection with the Purple Fox rootkit. The telegram installer attempts to evade detection utilizing small files with the first batch dropped from the initial "Telegram Desktop.exe” executable then copies specific files to the ProgramData folder, launching an executable and deleting the recently downloaded files. Following registry modifications, additional malicious files are downloaded initiating actions to run a new driver service, bypass UAC and stop AV. The final stages of the attack exfiltrate any collected information for AV products to the C2 server and download the purple fox rootkit.

     

Get trending threats published weekly by the Anvilogic team.

Sign Up Now