Malware

Purple Fox malware spread through fake Telegram installers

0

A malicious Telegram for Desktop installer distributes the Purple Fox malware to install further malicious payloads on infected devices.

According to a new research published by Minerva Labs, the attack is described as different from intrusions that usually take advantage of legitimate software for dropping malicious payloads.

The installer is a compiled AutoIt script named “Telegram Desktop.exe” that drops two files, an actual Telegram installer, and a malicious downloader.

While the legitimate Telegram installer dropped alongside the downloader isn’t executed, the AutoIT program runs the downloader.

The threat actor managed to leave most parts of the attack under the radar by separating the attack into several small files, most of which had very low detection rates by antivirus engines, with the final stage leading to Purple Fox rootkit infection.

Purple Fox which was first discovered in 2018, comes with rootkit capabilities that allow the malware to be planted beyond the reach of security solutions and evade detection. In March 2021, there were reports of its worm-like propagation feature, enabling the backdoor to spread more rapidly.

In October 2021, Trend Micro researchers uncovered a .NET implant dubbed FoxSocket deployed in conjunction with Purple Fox that takes advantage of WebSockets to contact its command-and-control (C2) servers for a more secure means of establishing communications.

In December 2021, Trend Micro also reported about the later stages of the Purple Fox infection chain, targeting SQL databases by inserting a malicious SQL common language runtime (CLR) module to achieve a persistent and stealthier execution and ultimately abuse the SQL servers for illicit cryptocurrency mining.

The researcher Natalie Zargarov, stated that they found a large number of malicious installers delivering the same Purple Fox rootkit version using the same attack chain. They think that some were delivered via email, while others were downloaded from phishing websites.

Image Credits : Technoidhost

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Uber dismisses vulnerability that lets you send email from Uber.com

Previous article

Apple iOS vulnerable to HomeKit doorLock bug

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *