A malicious Telegram for Desktop installer distributes the Purple Fox malware to install further malicious payloads on infected devices.
According to a new research published by Minerva Labs, the attack is described as different from intrusions that usually take advantage of legitimate software for dropping malicious payloads.
The installer is a compiled AutoIt script named “Telegram Desktop.exe” that drops two files, an actual Telegram installer, and a malicious downloader.
While the legitimate Telegram installer dropped alongside the downloader isn’t executed, the AutoIT program runs the downloader.
The threat actor managed to leave most parts of the attack under the radar by separating the attack into several small files, most of which had very low detection rates by antivirus engines, with the final stage leading to Purple Fox rootkit infection.
Purple Fox which was first discovered in 2018, comes with rootkit capabilities that allow the malware to be planted beyond the reach of security solutions and evade detection. In March 2021, there were reports of its worm-like propagation feature, enabling the backdoor to spread more rapidly.
In October 2021, Trend Micro researchers uncovered a .NET implant dubbed FoxSocket deployed in conjunction with Purple Fox that takes advantage of WebSockets to contact its command-and-control (C2) servers for a more secure means of establishing communications.
In December 2021, Trend Micro also reported about the later stages of the Purple Fox infection chain, targeting SQL databases by inserting a malicious SQL common language runtime (CLR) module to achieve a persistent and stealthier execution and ultimately abuse the SQL servers for illicit cryptocurrency mining.
The researcher Natalie Zargarov, stated that they found a large number of malicious installers delivering the same Purple Fox rootkit version using the same attack chain. They think that some were delivered via email, while others were downloaded from phishing websites.
Image Credits : Technoidhost














Comments