Last seven days
- First activity
- Aug 30, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 8 IP / 72 hostnames
PurpleFox is a modular Windows malware family active since at least 2018 that combines exploit-driven propagation, rootkit-enabled stealth, backdoor functionality, downloader behavior, and botnet operations.
Profile source: Mallory opens in a new tabPurpleFox
PurpleFox is a modular Windows malware family active since at least 2018 that combines exploit-driven propagation, rootkit-enabled stealth, backdoor functionality, downloader behavior, and botnet operations. It has also been closely associated with delivery of DirtyMoe, and some reporting has used the two names interchangeably, though PurpleFox is widely recognized as its own malware family and exploit ecosystem.
PurpleFox commonly infects systems through malicious MSI installers, exploit-kit activity, and other staged delivery chains. Observed distribution methods include drive-by exploitation through the PurpleFox exploit kit, abuse of WPAD for zero-click delivery, PowerShell-based download chains, fake software or trojanized installers, and MSHTA-assisted execution chains. It has incorporated multiple Windows and Internet Explorer vulnerabilities over time, including browser exploitation for initial compromise and local privilege-escalation exploits to obtain elevated execution before installing its components.
A defining feature of PurpleFox is its rootkit-backed persistence and defense evasion. Its installation workflow has been observed modifying system configuration and scheduling replacement of legitimate service-related DLLs so that malicious code executes with SYSTEM privileges after reboot. PurpleFox deploys additional DLLs and a kernel-mode rootkit component that can hide malware files, registry keys, processes, and related artifacts, making eradication difficult and enabling long dwell times on compromised hosts.
PurpleFox supports downloader and backdoor roles. It can retrieve and install second-stage payloads, maintain command-and-control communications, fingerprint infected hosts, execute commands, enumerate files and directories, create or terminate processes, perform WMI and DNS queries, and exfiltrate data. Newer variants have used WebSocket-based command and control with encrypted session establishment, reflecting continued development and operational maturity.
PurpleFox has also demonstrated self-propagation and botnet behavior. Reported campaigns indicate it can spread by exploiting known vulnerabilities and by brute-forcing passwords, and it has been described as capable of distributed denial-of-service activity. In incident investigations, PurpleFox infections have also co-occurred with cryptocurrency mining payloads such as XMRig, indicating use for monetization beyond simple access operations.
Geographically, PurpleFox infrastructure and victimology have been observed across multiple regions, including Ukraine, the Middle East, and parts of Asia, with repeated reporting of substantial infrastructure presence in China. PurpleFox remains active into 2026 and continues to evolve its delivery chains, privilege-escalation arsenal, and stealth mechanisms.
C2 tracking
Derp observations, rolling seven-day window
Samples
2373dac86dbe2f62f37a614c7b66646aaab87343e0f3dc77e90cde201e863082 6f73f5d8d8e7843414f4af4d1325841cf07dd769e9661462df3368083819a975 a3ba0f671df55e1515a13ab81946ac13deb8241fa2f4d9f2a7a6ab2cca26053e ad4ec9f24f9bb9a14da8c61b64959fd9d01819f4873703ddcf84fa131061125d ecdc7cb90d662c515a408c13a42c01461a493280515ddbe2b2337cb1ad0cc68e 02d449dd871914f962ca98f83599bbd68c58b35400584ab0a656972f1ef12b28 16b5ea098d0b91e70cfc488fed7a6093540a7418b85208b87e0ea9c5e887a2c2 805a8cd3da6debb4eafc2e5b226c8502df6c866b88aa68c0e51af82d9d78d5f4 92e73f111805c0ae4d88836a01cd29262903a916c91d9dc8d59a13f3c4a36235 be7e226cb06d7fd6558fc4efb115312759b7e6a4f433662b536ad71b5eea389a Reported operators
The Computer Emergency Response Team in Ukraine (CERT-UA) is warning about a PurpleFox malware campaign that has infected at least 2,000 computers in the country. PurpleFox (or 'DirtyMoe') is a modular Windows botnet malware first spotted in 2018 that comes with a rootkit module allowing it to hide and persist between device reboots.
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.