Threat actors leveraged a malicious Telegram installer to infect users with the Purple Fox rootkit.

A Case Study in Evasion

With the help of MalwareHunterTeam, Minerva Labs looked into a malicious Telegram installer and found that it was a compiled AutoIt script called ‘Telegram Desktop.exe.’

The script created a new folder and dropped both a legitimate Telegram installer and a malicious downloader into it. The former didn’t factor into the attack chain. The same can’t be said about the latter, however.

Upon execution, the malicious downloader contacted a command and control (C&C) server and downloaded two files into a newly created folder. One of those resources, ‘7zz.exe,’ contained another file called ‘ojbke.exe’ that, when run with the ‘-a’ argument, reflectively loaded a DLL file.

This item led the attack flow to use some more files for the purpose of shutting down antivirus processes. It was then that the campaign took advantage of its C&C server to gather the hostname, CPU and other information from a victim.

It also checked to see if various antivirus solutions were running on the victim’s machine. At that point, the campaign delivered all that data to the C&C server.

The server was down at the time of Minerva Labs’ analysis. But upon reviewing the IP address, the researchers found that the attack concluded by downloading and running Purple Fox. Further review revealed that malicious installers were delivering the same rootkit via email, presumably from phishing websites.

Other Recent Attack Attempts Involving Purple Fox

The attack campaign discussed above wasn’t the first time that the Purple Fox rootkit made news in the past few years. In September 2019, researchers witnessed the RIG exploit kit sending out a new Purple Fox variant. The threat used one of three methods to redirect visitors to a malicious PowerShell command for the purpose of installing the rootkit.

In 2021, Guardicore Labs detected an active malware campaign targeting Windows machines. This operation differed from previous attacks involving Purple Fox in that it didn’t leverage phishing emails or exploit kits. Instead, it used SMS password brute forcing, a tactic which enabled the rootkit to propagate as a worm across web-facing Windows machines.

How to Defend Against Purple Fox Attack Attempts

Businesses can defend against the Purple Fox attack attempts discussed above by investing in their anti-phishing measures. Those defenses include using awareness training to cultivate employees’ knowledge of new phishing attack campaigns. They also consist of using URL blocking, spam controls, multifactor authentication and other technical defensive measures.

At the same time, businesses and agencies need to minimize the risk of attackers using exploit kits and SMS vulnerabilities to infect them with threats like Purple Fox. They can do this by prioritizing and remediating vulnerabilities affecting their systems using a vulnerability management program.

More from News

LastPass Breaches Cast Doubt on Password Manager Safety

In 2022, LastPass suffered a string of security breaches which sparked concern among cyber professionals and those impacted by the intrusions. Some called into question the way LastPass handled and responded to the incident. In addition, the situation ignited a wider conversation about the risks linked to utilizing password managers.A password manager helps users generate strong passwords and safeguards them within a digital locker. A master password secures all data, which enables users to conveniently access all their passwords for…

Good Guys Decrypt Ransomware Targeting Charitable Groups

Imagine you’re an IT manager amid a ransomware attack. While your team scrambles for solutions, the intruders demand a ransom. Of course, you don’t want to pay; you just want your files back. But as time ticks by and the extortionists turn up the heat, your bosses are about to give in and pay the ransom. But then, the FBI calls. “Don’t pay,” the agent says. “We’ve found someone who can crack the encryption.” Sound too good to be true?…

Threat Groups Offer $240k Salary to Tech Jobseekers

Dark web forums are home to various individuals interested in conducting illicit or questionable activities. These forums offer opportunities such as the transaction of stolen data, Malware-as-a-Service, hacking services and invitations to collaborate in hacktivism. Cyber crime team members are recruited directly from the source: the dark web. What does this activity look like? Kaspersky recently conducted an analysis of 155 dark web forums from January 2020 to June 2022. They examined job postings and resumes that contained information about…

Cryptocurrency-Related Crime Boomed in 2022

Cryptocurrency crime is flourishing, according to multiple year-end reports. For starters, cryptocurrency losses due to cyber theft rose to $3.7 billion last year. That’s a 58% increase over the $2.3 billion malicious actors stole from investors and exchanges in 2021, according to a new report by Immunefi. Meanwhile, illicit cryptocurrency activity reached an all-time high of $20.1 billion in 2022, a $2.1 billion increase from the previous year. The escalating U.S. sanctions targeting digital currencies have contributed to that rise,…