Threat actors leveraged a malicious Telegram installer to infect users with the Purple Fox rootkit.

A case study in evasion

With the help of MalwareHunterTeam, Minerva Labs looked into a malicious Telegram installer and found that it was a compiled AutoIt script called ‘Telegram Desktop.exe.’

The script created a new folder and dropped both a legitimate Telegram installer and a malicious downloader into it. The former didn’t factor into the attack chain. The same can’t be said about the latter, however.

Upon execution, the malicious downloader contacted a command and control (C&C) server and downloaded two files into a newly created folder. One of those resources, ‘7zz.exe,’ contained another file called ‘ojbke.exe’ that, when run with the ‘-a’ argument, reflectively loaded a DLL file.

This item led the attack flow to use some more files for the purpose of shutting down antivirus processes. It was then that the campaign took advantage of its C&C server to gather the hostname, CPU and other information from a victim.

It also checked to see if various antivirus solutions were running on the victim’s machine. At that point, the campaign delivered all that data to the C&C server.

The server was down at the time of Minerva Labs’ analysis. But upon reviewing the IP address, the researchers found that the attack concluded by downloading and running Purple Fox. Further review revealed that malicious installers were delivering the same rootkit via email, presumably from phishing websites.

Other recent attack attempts involving Purple Fox

The attack campaign discussed above wasn’t the first time that the Purple Fox rootkit made news in the past few years. In September 2019, researchers witnessed the RIG exploit kit sending out a new Purple Fox variant. The threat used one of three methods to redirect visitors to a malicious PowerShell command for the purpose of installing the rootkit.

In 2021, Guardicore Labs detected an active malware campaign targeting Windows machines. This operation differed from previous attacks involving Purple Fox in that it didn’t leverage phishing emails or exploit kits. Instead, it used SMS password brute forcing, a tactic which enabled the rootkit to propagate as a worm across web-facing Windows machines.

How to defend against Purple Fox attack attempts

Businesses can defend against the Purple Fox attack attempts discussed above by investing in their anti-phishing measures. Those defenses include using awareness training to cultivate employees’ knowledge of new phishing attack campaigns. They also consist of using URL blocking, spam controls, multifactor authentication and other technical defensive measures.

At the same time, businesses and agencies need to minimize the risk of attackers using exploit kits and SMS vulnerabilities to infect them with threats like Purple Fox. They can do this by prioritizing and remediating vulnerabilities affecting their systems using a vulnerability management program.

More from News

Securing critical infrastructure with the carrot and stick

4 min read - It wasn’t long ago that cybersecurity was a fringe topic of interest. Now, headline-making breaches impact large numbers of everyday citizens. Entire cities find themselves under cyberattack. In a short time, cyber has taken an important place in the national discourse. Today, governments, regulatory agencies and companies must work together to confront this growing threat. So how is the federal government bolstering security for critical infrastructure? It looks like they are using a carrot-and-stick approach. Back in March 2022, the…

650,000 cyber jobs are now vacant: How to tackle the risk

4 min read - How far is the United States behind in filing cybersecurity jobs? As per Rep. Andrew Garbarino, R-N.Y., Chairman of the HHS Cybersecurity and Infrastructure Protection Subcommittee, overseas adversaries have a workforce advantage over FBI cyber personnel of 50 to one. His statements were made during a recent subcommittee hearing titled “Growing the National Cybersecurity Talent Pipeline.” Meanwhile, recent CyberSeek data shows over 650,000 cyber jobs to fill nationwide. Given the rising rate of cyberattacks, these numbers are truly alarming. How…

Will data backups save you from ransomware? Think again

4 min read - Backups are an essential part of any solid anti-ransomware strategy. In fact, research shows that the median recovery cost for ransomware victims that used backups is half the cost incurred by those that paid the ransom. But not all data backup approaches are created equal. A separate report found that in 93% of ransomware incidents, threat actors actively target backup repositories. This results in 75% of victims losing at least some of their backups during the attack, and more than…

Should you worry about state-sponsored attacks? Maybe not.

4 min read - More than ever, state-sponsored cyber threats worry security professionals. In fact, nation-state activity alerts increased against critical infrastructure from 20% to 40% from 2021 to 2022, according to a recent Microsoft Digital Defense Report. With the advent of the hybrid war in Ukraine, nation-state actors are launching increasingly sophisticated attacks. But is this the most prominent danger facing companies today? While nation-state-based attacks cannot be ignored, it looks like insider cyber incidents are far more common. In fact, for the…