Menu

Post image 1
Post image 2
Post image 3
Post image 4
Post image 5
Post image 6
Post image 7
Post image 8
Post image 9
Post image 10
Post image 11
Post image 12
Post image 13
Post image 14
1 / 14
0

Purple Fox Rootkit Now Propagates as a Worm

Akamai·Guardicore Labs Team·about 1 month ago
#VhFuODGU
Reading 0:00
15s threshold

Blog Security Purple Fox Rootkit Now Propagates as a Worm The Guardicore Labs Team is a global research group, consisting of hackers, cybersecurity researchers, and industry experts. by Amit Serper and Ophir Harpaz \r\n Executive Summary \r\n \r\n Purple Fox is an active malware campaign targeting Windows machines. \r\n \r\n Up until recently, Purple Fox’s operators infected machines by using exploit kits and phishing emails. \r\n \r\n Guardicore Labs have identified a new infection vector of this malware in which internet-facing Windows machines are being breached through SMB password brute force. \r\n \r\n Guardicore Labs have also identified Purple Fox’s vast network of compromised servers hosting its dropper and payloads. These servers appear to be compromised Microsoft IIS 7.5 servers. \r\n \r\n The Purple Fox malware includes a rootkit that allows the threat actors to hide the malware on the machine and make it difficult to detect and remove.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More