PurpleFox Returns: Insights On Its Recent Spam Campaign
ID: fe1361b3-e0e7-5ca7-a687-ba1e8cfac517
STIX ID: report--fe1361b3-e0e7-5ca7-a687-ba1e8cfac517
Feed Name: Cyble Blog
Cyble Research and Intelligence Labs analyzed a spam campaign that distributes PurpleFox: malicious Word attachments trigger VBA macros which download a PowerShell 'jpg' downloader that fetches a PNG containing a second-stage PowerShell script via steganography; that script disables protections and repeatedly installs an MSI (disguised as a JPG) that drops and sideloads PurpleFox DLLs. The report includes technical analysis, MITRE ATT&CK technique mappings, and IOCs (file hashes, URLs, and domain) to aid detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
