logo

PurpleFox malware infects thousands of computers in Ukraine

ID: 0edee21d-f6d6-597d-8741-1d6b7026c72c

STIX ID: report--0edee21d-f6d6-597d-8741-1d6b7026c72c

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-02-01

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

CERT-UA warns of an active PurpleFox (aka DirtyMoe) malware campaign observed in Ukraine that has infected at least 2,000 systems. PurpleFox is a modular Windows botnet with a rootkit for persistence, functions as a downloader/backdoor and DDoS bot, and spreads via laced MSI installers, known exploits, and brute-force. The advisory includes IoCs, recommended detection steps (registry checks, log/event/port checks, suspicious files/services), and removal guidance including offline disk cleaning and firewall/hardening measures to prevent re-infection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.