Skip to content

PurpleFox

PurpleFox is a modular Windows malware family active since at least 2018 that combines exploit-driven propagation, rootkit-enabled stealth, backdoor functionality, downloader behavior, and botnet operations.

Profile source: Mallory opens in a new tab

PurpleFox

Family profile

PurpleFox is a modular Windows malware family active since at least 2018 that combines exploit-driven propagation, rootkit-enabled stealth, backdoor functionality, downloader behavior, and botnet operations. It has also been closely associated with delivery of DirtyMoe, and some reporting has used the two names interchangeably, though PurpleFox is widely recognized as its own malware family and exploit ecosystem.

PurpleFox commonly infects systems through malicious MSI installers, exploit-kit activity, and other staged delivery chains. Observed distribution methods include drive-by exploitation through the PurpleFox exploit kit, abuse of WPAD for zero-click delivery, PowerShell-based download chains, fake software or trojanized installers, and MSHTA-assisted execution chains. It has incorporated multiple Windows and Internet Explorer vulnerabilities over time, including browser exploitation for initial compromise and local privilege-escalation exploits to obtain elevated execution before installing its components.

A defining feature of PurpleFox is its rootkit-backed persistence and defense evasion. Its installation workflow has been observed modifying system configuration and scheduling replacement of legitimate service-related DLLs so that malicious code executes with SYSTEM privileges after reboot. PurpleFox deploys additional DLLs and a kernel-mode rootkit component that can hide malware files, registry keys, processes, and related artifacts, making eradication difficult and enabling long dwell times on compromised hosts.

PurpleFox supports downloader and backdoor roles. It can retrieve and install second-stage payloads, maintain command-and-control communications, fingerprint infected hosts, execute commands, enumerate files and directories, create or terminate processes, perform WMI and DNS queries, and exfiltrate data. Newer variants have used WebSocket-based command and control with encrypted session establishment, reflecting continued development and operational maturity.

PurpleFox has also demonstrated self-propagation and botnet behavior. Reported campaigns indicate it can spread by exploiting known vulnerabilities and by brute-forcing passwords, and it has been described as capable of distributed denial-of-service activity. In incident investigations, PurpleFox infections have also co-occurred with cryptocurrency mining payloads such as XMRig, indicating use for monetization beyond simple access operations.

Geographically, PurpleFox infrastructure and victimology have been observed across multiple regions, including Ukraine, the Middle East, and parts of Asia, with repeated reporting of substantial infrastructure presence in China. PurpleFox remains active into 2026 and continues to evolve its delivery chains, privilege-escalation arsenal, and stealth mechanisms.

Capabilities

  • Brute Force
  • Ddos
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Privilege Escalation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 30, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
8 IP / 72 hostnames

Leading locations

  • US50
  • IE13
  • CN6
  • HK5
  • DE2
  • RU2
  • FI1
  • NL1

Leading providers

  • Amazon.com, Inc.30
  • Amazon.com, Inc.25
  • Google LLC3
  • Akamai Connected Cloud2
  • cognetcloud INC2
  • CTG Server Limited2

Infrastructure traits

  • Hosting 73

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
UAC-0027

The Computer Emergency Response Team in Ukraine (CERT-UA) is warning about a PurpleFox malware campaign that has infected at least 2,000 computers in the country. PurpleFox (or 'DirtyMoe') is a modular Windows botnet malware first spotted in 2018 that comes with a rootkit module allowing it to hide and persist between device reboots.

Exploited software

Vulnerabilities linked to PurpleFox

7 CVEs

MITRE ATT&CK

PurpleFox in ATT&CK

27 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.