MITRE ATT&CK
PurpleFox in ATT&CK
12 distinct techniquesReporting
Research mentioning PurpleFox
Как повысить защищенность организации: опыт Kaspersky Compromise Assessment | Securelist
...удалось найти два скрытых объекта: код руткита PurpleFox, внедренный в легитимные процессы svchost.exe...
How to improve your organization’s security based on compromise assessment findings | Securelist
Two hidden objects were identified: PurpleFox rootkit code injected into legitimate svchost.exe processes on several critical servers. XMRig cryptocurrency miner signatures residing inside the same compromised svchost.exe instances.
Hackers Abuse MSHTA Legacy Windows Tool to Deliver LummaStealer and Amatera Malware
The campaigns observed cover several malware families, including LummaStealer, Amatera, ClipBanker, CountLoader, Emmenhtal Loader, and PurpleFox.
Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows
MSHTA is not only used in commodity-stealing and loader campaigns. It also appears in delivery chains associated with PurpleFox, a more advanced and persistent malware family that has remained active for years. Since emerging in 2018, PurpleFox has continued to expand its arsenal and remains active in 2026.