Breaking

Purple Fox malware is actively distributed via Telegram Installers

Purple Fox malware is distributed via malicious Telegram Desktop Installer, this malware installs further payloads on the affected devices.

The file “Telegram Desktop.exe” comes with two files, an original installer file and a malicious downloader.The legitimate installer isn’t executed as the AutoIT program runs the TextInputh.exe file.

Understanding the Purple Fox Malware campaign

This TextInputh.exe when executed will create a new folder called “1640618495” under the C:\Users\Public\Videos\ location and then communicate with C2 to download a RAR and 7z utility. The RAR file contains the configuration and payload file, when the 7z program unzips everything to the ProgramData folder.

As per Minerva Labs, TextInputh.exe does the following actions onto the compromised machine,

  • Copies 360.tct with “360.dll” name —> rundll3222.exe —-> svchost.txt to the ProgramData folder
  • Executes ojbk.exe with the “ojbk.exe -a” command line
  • Deletes 1.rar and 7zz.exe and exits the process

Later, a  registry key is created and a DLL disables UAC the payload is executed and the following five additional files are dropped into the infected system,

  • Calldriver.exe
  • Driver.sys
  • dll.dll
  • kill.bat
  • speedmem2.hg

These extra files is used to block the initiation of 360 AV processes and avoid detection of Purple Fox on the affected device.  Moving further the malware gather system details, scans for security tools running in the device and then send the hard coded C2 address.

Complete capabilities of Purple Fox malware

After this process, Purple Fox is downloaded from the C2 in the form of an .msi file that has encrypted shellcode for both 64- and 32- bit systems. Once the Purple Fox is executed, the compromised devices are restarted for the registry settings to work, especially the disabled User Account Control (UAC).

To achieve this, the dll.dll file sets the following three registry keys to 0:

  1. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System ConsentPromptBehaviorAdmin
  2. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
  3. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\PromptOnSecureDesktop

Disabling bypassing UAC is vital because it deploys viruses and malware with administrator privileges. In general, UAC prevents the installation of unauthorized apps and the change of system settings, to be active on all Windows devices.

When disabled Purple Fox will perform malicious functions like searching of file, exfiltration, deletion of data, process killing, downloading and running code. and even worming to other Windows devices. Malware similar to Purple Fox are actively being distributed via Youtube Videos, malicious websites, and other forum sites.

Subscribe to our newsletter for daily alerts on cyber events, you can also follow us on Facebook, Linkedin, Instagram, Twitter and Reddit. You can reach out to us via Twitter or Facebook, for any advertising requests.

Share the article with your friends
John Greenwood

He has been working with Cybersec and Infosec market for 12+ years now. Passionate about AI, Cybersecurity, Info security, Blockchain and Machine Learning. When he is not occupied with cybersecurity, he likes to go on bike rides!

Recent Posts

Recast Software: Advanced Endpoint Management and Security Tools for IT Teams

Recast Software offers a suite of tools designed to enhance and simplify endpoint management in…

4 months ago

Patch My PC: Streamlined Software Management for ConfigMgr and Intune

Patch My PC is a widely-used solution that simplifies third-party application management by automating app…

4 months ago

Best Microsoft Intune Alternatives: Top 5 MDMs to Consider

Explore the top 5 best Microsoft Intune alternatives, comparing key features, user reviews, and capabilities…

4 months ago

Top 7 Best Smartphones with Best Security Features in 2024

Discover the top 7 smartphones of 2024 with best security features, offering privacy, performance, and…

5 months ago

Top 11 Log Management Tools for Efficient System Management

Discover the top 11 log management tools for efficient system management and monitoring. Learn about…

6 months ago

Top 5 Threat Intelligence Tools For 2024

Explore the top 5 threat intelligence tools, their features, and how they enhance cybersecurity against…

6 months ago