HomeSecurityPurple Fox malware upgraded and targets new vulnerabilities

Purple Fox malware upgraded and targets new vulnerabilities

The developers behind the Purple Fox file-downloading malware recently upgraded their operations and are now targeting two new vulnerabilities to gain access to networks, according to a report from security firm Proofpoint.

Purple Fox targeted 30,000 users in 2018 alone, according to a previous report by TrendMicro.

The Purple Fox gang recently created a new exploit kit, called Purple Fox, replacing the RIG exploit kit it previously used to distribute the malware. This move allows the gang to eliminate the cost of purchasing a kit, according to a new report from Proofpoint.

In addition, Purple Fox now exploits two additional vulnerabilities. The first, reported as CVE-2020-0674, is an engine memory vulnerability in Internet Explorer that could allow attackers to take control of the system and execute remote code. The second vulnerability, CVE-2019-1458, is a local elevation of privilege vulnerability in certain versions of Windows.

Microsoft issued patches last year for each of these bugs, according to the report.

"As exploit kits have become more prevalent, the Purple Fox exploit kit continues to be updated and remains relevant with new exploits," said Sherrod DeGrippo, senior director of threat research at Proofpoint.

Purple Fox malware

Malware methods

“The goal of these attacks is to successfully exploit a vulnerable target so that they can execute PowerShell in a way that downloads additional malware,” DeGrippo says. Once deployed, the Purple Fox malware “ends up” in a rootkit to maintain persistence, he adds.

Purple Fox has been exploiting the two vulnerabilities since at least mid-June, DeGrippo notes.

In one incident observed by researchers, attackers exploited CVE-2020-0674 to launch a malicious attack using Internet Explorer's use of jscript.dll, a file system that allows Windows to function. The malicious script attempts to leak an address from the regular expression application within jscript.dll, Proofpoint reports.

The malicious JavaScript uses these leaked addresses to look for the Portable Executable header of jscript.dll, which is then used to locate an import descriptor containing the memory required to load the actual shellcode, the report says.

Malware distribution

Purple Fox is primarily used to distribute other types of malware, such as information stealers, cryptominers, ransomware , and Trojans, which are owned and operated by the threat actor developing the kit and are not sold for use by others, DeGrippo says.

The move to an internal exploit kit and targeting two new vulnerabilities shows that Purple Fox's creators are "making decisions based on cost savings and moving quickly to adapt to new developments that can allow them to expand their market," DeGrippo says.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS