PurpleFox malware infects thousands of computers in Ukraine
ID: 0edee21d-f6d6-597d-8741-1d6b7026c72c
STIX ID: report--0edee21d-f6d6-597d-8741-1d6b7026c72c
Feed Name: Bleeping Computer
CERT-UA warns of an active PurpleFox (aka DirtyMoe) malware campaign observed in Ukraine that has infected at least 2,000 systems. PurpleFox is a modular Windows botnet with a rootkit for persistence, functions as a downloader/backdoor and DDoS bot, and spreads via laced MSI installers, known exploits, and brute-force. The advisory includes IoCs, recommended detection steps (registry checks, log/event/port checks, suspicious files/services), and removal guidance including offline disk cleaning and firewall/hardening measures to prevent re-infection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
