Netskope Threat Labs

Purplefox

ATP Sandbox Adv. HeuristicsNetskope IPS

Purplefox is a malware family that abuses legitimate Windows components, including an installer function that downloads and executes payload files, to establish itself on infected systems. It injects a driver with rootkit capability into a suspended service host process to hide its files and registry entries, and later versions abused open source code and file utility software to conceal its components from analysis.

First seen
April 2022
Last seen
September 2026
PurpleFox
Alert Name
ByteCode-MSIL.Backdoor.Purplefox
Script-JS.Trojan.PurpleFox
Script-PowerShell.Trojan.Purplefox
Win32.Backdoor.Purplefox
Win32.Backdoor.PurpleFox
Win32.Trojan.Purplefox
Win32.Trojan.PurpleFox
Win64.Trojan.Purplefox
Win64.Trojan.PurpleFox