Skip to main content

Beware of fake Telegram Messenger App Hacking PCs with Purple Fox Malware


The Telegram messaging app Trojan installers are  used to deploy the Windows-based Purple Fox backdoor to compromised systems. That's according to new research published by Minerva Labs, which describes the attack as different from intruders that typically exploit legitimate software to release malicious payloads. 

"This threat actor was able to keep most  of the attack under the radar by breaking the attack down into several small files, most of which had very low detection rates by the [antivirus] engines,  the last step leading  Purple Fox rootkit infection, said researcher Natalie Zargarov.

First discovered in 2018, Purple Fox comes with rootkit capabilities that allow the malware to be planted beyond the reach of security solutions and evade detection. A March 2021 report from Guardicore  detailed its worm-like propagation feature, enabling the backdoor to spread more rapidly.

Then, in October 2021, Trend Micro researchers discovered a .NET implant dubbed FoxSocket distributed in partnership with Purple Fox that uses WebSockets to contact its command and control (C2) servers for a more secure way to establish communications.

"The capabilities of the Purple Fox rootkit make it more capable of achieving its goals in a more stealthy manner," the researchers noted. “They allow Purple Fox to persist on affected systems and deliver additional payloads to affected systems.

Last but not least, in December 2021, Trend Micro also  shed light on the later stages of the Purple Fox infection chain, targeting SQL databases by inserting a malicious SQL common language runtime (CLR) module to achieve a persistent and stealthier execution and ultimately abuse the SQL servers for illicit cryptocurrency mining.


The new  chain of attacks observed by Minerva begins with a Telegram installer file, an AutoIt script that publishes a legitimate installer for the chat app, and a malicious downloader called "TextInputh.exe", the latter being executed to retrieve the next malware from the C2 server.

 Then the downloaded files  block the processes associated with the different antivirus engines, before moving on to the final step of downloading and running the Purple Fox rootkit from a  remote server which is now down. installers providing the same version of the Purple Fox rootkit  using the same attack chain, ”Zargarov said.

“ Some appear to have been delivered by email, while others, we assume, were downloaded from websites phishing. The beauty of this attack is that each step is separate for a different file, which is unnecessary without all of the files.

Source: The Hacker News




from TechCrunch https://ift.tt/3mYejGy
via IFTTT

Comments

Popular posts from this blog

The Silent Revolution of On-Device AI: Why the Cloud Is No Longer King

Introduction For years, artificial intelligence has meant one thing: the cloud. Whether you’re asking ChatGPT a question, editing a photo with AI tools, or getting recommendations on Netflix — those decisions happen on distant servers, not your device. But that’s changing. Thanks to major advances in silicon, model compression, and memory architecture, AI is quietly migrating from giant data centres to the palm of your hand. Your phone, your laptop, your smartwatch — all are becoming AI engines in their own right. It’s a shift that redefines not just how AI works, but who controls it, how private it is, and what it can do for you. This article explores the rise of on-device AI — how it works, why it matters, and why the cloud’s days as the centre of the AI universe might be numbered. What Is On-Device AI? On-device AI refers to machine learning models that run locally on your smartphone, tablet, laptop, or edge device — without needing constant access to the cloud. In practi...

Apple’s AI Push: Everything We Know About Apple Intelligence So Far

Apple’s WWDC 2025 confirmed what many suspected: Apple is finally making a serious leap into artificial intelligence. Dubbed “Apple Intelligence,” the suite of AI-powered tools, enhancements, and integrations marks the company’s biggest software evolution in a decade. But unlike competitors racing to plug AI into everything, Apple is taking a slower, more deliberate approach — one rooted in privacy, on-device processing, and ecosystem synergy. If you’re wondering what Apple Intelligence actually is, how it works, and what it means for your iPhone, iPad, or Mac, you’re in the right place. This article breaks it all down.   What Is Apple Intelligence? Let’s get the terminology clear first. Apple Intelligence isn’t a product — it’s a platform. It’s not just a chatbot. It’s a system-wide integration of generative AI, machine learning, and personal context awareness, embedded across Apple’s OS platforms. Think of it as a foundational AI layer stitched into iOS 18, iPadOS 18, and m...

Max Q: Galactic

Hello and welcome back to Max Q! Happy Memorial Day everyone. In this issue: Astranis’ novel approach to GEO satellites Virgin Galactic’s return to the skies News from SpaceX, and more Astranis’ novel approach to internet satellites is starting to pay off Astranis , a satellite internet startup based in San Francisco, said Wednesday that its first spacecraft completed a milestone test and will start bringing broadband access to rural Alaskans as soon as mid-June. It’s a major step for the company, which was founded in 2015 by John Gedmark and Ryan McLinko. By taking a first principles approach to satellite development, the pair bet that they could make a smaller, cheaper spacecraft for geosynchronous orbit — the orbit farthest from Earth and arguably the most inhospitable — and use them to bring internet to millions, or even billions, of people around the globe. Their bet is paying off: The company’s first satellite, Arcturus, launched on a Falcon Heavy at the end of April. W...