Frequently Asked Questions

Threat Intelligence & Technical Analysis

What is the Purple Fox rootkit and how does it spread via a malicious Telegram installer?

The Purple Fox rootkit is a sophisticated malware that can be delivered through a malicious Telegram installer. The attack begins with an AutoIt script that drops both a legitimate Telegram installer and a malicious downloader (TextInputh.exe). This downloader creates new folders, downloads additional payloads from a command-and-control (C&C) server, and executes a series of files designed to disable antivirus software and escalate privileges. The final stage involves downloading and executing the Purple Fox rootkit, which uses the 'MsiInstallProductA' function to install an encrypted payload. Note: This attack specifically targets Windows systems and employs advanced evasion and persistence techniques. Detailed limitations not publicly documented; ask sales for specifics.

How does the attack chain disable antivirus software during the Purple Fox infection?

The attack chain drops and executes several files, including Calldriver.exe and Driver.sys, which are used to shut down and block the initiation of multiple antivirus processes from kernel space. The malware checks for the presence of over 30 different antivirus and security products, such as 360 Total Security, Kaspersky, McAfee, Avast, and others. If detected, it attempts to terminate or bypass them to ensure the rootkit can execute undetected. Note: The effectiveness of these techniques may vary depending on the security configuration of the target system.

What privilege escalation and persistence techniques are used in the Purple Fox Telegram installer attack?

The attack uses a UAC bypass technique via the CMSTPLUA COM interface, which is also used by ransomware families like LockBit and BlackMatter. It drops and executes a DLL (dll.dll) with elevated privileges and creates new registry keys for persistence. The malware also leverages the 'PendingFileRenameOperations' registry value to ensure components are renamed and persist after system reboot. Note: These techniques are specific to Windows environments and may not be effective on systems with advanced endpoint protection or custom configurations.

Features & Capabilities

What types of threats can Cymulate validate?

Cymulate can validate a wide range of threats, including advanced persistent threats (APTs), malware, phishing attacks, ransomware, insider threats, network-based attacks, and web application attacks. The platform uses up-to-date threat intelligence and attack simulations to ensure comprehensive coverage against the latest cyber threats. Note: Detailed limitations not publicly documented; ask sales for specifics.

What features does Cymulate offer for exposure management and threat simulation?

Cymulate provides a user-friendly dashboard, extensive threat simulation capabilities, updated malware Indicators of Compromise (IOCs), customizable reports, and user notifications. These features allow organizations to simulate emerging threats effectively and manage exposure with actionable insights. Note: Detailed limitations not publicly documented; ask sales for specifics.

What is Cymulate Threat Studio and how does it help security teams?

Cymulate Threat Studio enables teams to build and customize attack simulations to validate defenses. It allows organizations to scale offensive testing with custom attacks tailored to their environment. For more details, visit the Threat Studio page. Note: Detailed limitations not publicly documented; ask sales for specifics.

What is the benefit of Cymulate's Immediate Threats module?

Cymulate's Immediate Threats module provides rapid updates on new attacks, allowing organizations to quickly assess their IT estate for risk exposure and implement remedial actions. This enables fast response to emerging threats, as noted by a Penetration Tester. Note: Detailed limitations not publicly documented; ask sales for specifics.

Use Cases & Benefits

Who can benefit from using Cymulate?

Cymulate is designed for business leaders (CISOs, VPs of Security), technical stakeholders (Directors of SecOps, SOC Leaders, Detection Engineers), security teams, and related stakeholders such as Red Teams, Vulnerability Management, GRC/Compliance, and IT/Infrastructure teams. It is suitable for organizations of all sizes and industries, including finance, healthcare, IT services, retail, and manufacturing. Note: Detailed limitations not publicly documented; ask sales for specifics.

What business impact can customers expect from using Cymulate?

Organizations using Cymulate have reported a 30% improvement in threat prevention, a 52% reduction in critical exposures, a 60% increase in operational efficiency, 40X faster threat validation, and an 85% improvement in detection accuracy. For example, Hertz Israel achieved an 81% reduction in cyber risk within four months. Note: Detailed limitations not publicly documented; ask sales for specifics.

Implementation & Ease of Use

How easy is it to implement Cymulate and get started?

Cymulate is designed for rapid deployment and ease of use. It operates in agentless mode, requiring no additional hardware or complex configurations. Customers can start running simulations almost immediately after deployment. The platform is intuitive and requires minimal training, as noted by customer testimonials. Support is available via email and chat, and educational resources such as webinars and e-books are provided. Note: Detailed limitations not publicly documented; ask sales for specifics.

What feedback have customers provided about Cymulate's ease of use?

Customers consistently highlight Cymulate's ease of use and intuitive design. For example, Ariel Kashir (CISO) stated, "Cymulate is a must if you want to ensure your organization is safe from cyber threats. It's easy to use, intuitive, and the customer support is unparalleled." Raphael Ferreira (Cybersecurity Manager) noted, "Cymulate is easy to implement and use—all you need to do is click a few buttons, and you receive a lot of practical insights into how you can improve your security posture." Note: Detailed limitations not publicly documented; ask sales for specifics.

Pricing & Plans

What is Cymulate's pricing model?

Cymulate uses a subscription-based pricing model that is customized to each organization's requirements. The subscription fee depends on the package selected, the number of assets covered, and the scenarios and vectors chosen. For a detailed quote, you can schedule a demo with the Cymulate team. Note: Exact pricing is not publicly listed; contact sales for specifics.

Security & Compliance

What security and compliance certifications does Cymulate hold?

Cymulate holds several certifications, including SOC2 Type II (covering security, availability, confidentiality, and privacy), ISO 27001:2013 (Information Security Management), ISO 27701 (Privacy Information Management), ISO 27017 (Cloud Security), and CSA STAR Level 1 (Cloud Controls Matrix compliance). For more details, visit the Security at Cymulate page. Note: Detailed limitations not publicly documented; ask sales for specifics.

Integrations & Technical Documentation

What integrations does Cymulate support?

Cymulate supports over 50 integrations across various security technologies, including Akamai Guardicore (Network), AWS GuardDuty (Cloud Security), BlackBerry Cylance OPTICS (EDR), Carbon Black EDR, Check Point CloudGuard, Cisco Umbrella (Web Gateway), and CrowdStrike Falcon (SIEM). For a full list, visit the technology alliances and partners page. Note: Integration availability may depend on your package and environment.

Where can I find technical documentation about Cymulate's platform and features?

Technical documentation is available for download, including the Exposure Management Platform Whitepaper, Threat Studio Data Sheet, Detection Engineering Guide, Custom Attacks Data Sheet, and an overview of technology partnerships and integrations. Access these resources at the Cymulate Resources page. Note: Some documents may require registration or a Cymulate account.

Competition & Comparison

How does Cymulate compare to AttackIQ?

Cymulate delivers a comprehensive threat scenario library and AI-powered capabilities to streamline workflows and accelerate security posture. AttackIQ focuses on automated security validation but lacks Cymulate's innovation, threat coverage, and ease of use. Cymulate is built for organizations seeking broad threat coverage and rapid validation; AttackIQ may be suitable for teams focused on traditional BAS workflows. Note: AttackIQ may be preferred by organizations with existing investments in their ecosystem. Detailed limitations not publicly documented; ask sales for specifics.

How does Cymulate compare to Mandiant Security Validation?

Mandiant is one of the original BAS platforms but has seen little innovation in the past five years. Cymulate continually innovates with AI and automation, expanding into exposure management. Cymulate is suitable for organizations seeking continuous improvement and measurable outcomes; Mandiant may be preferred by teams with legacy BAS requirements. Note: Mandiant may offer integrations or features not present in Cymulate. Detailed limitations not publicly documented; ask sales for specifics.

Cymulate named a Customers' Choice in 2026 Gartner® Peer Insights™
Learn More
New: Cymulate Cowork for Agentic Cyber Defense Engineering
Learn More
New Bitsight Integration: Turn Threat Intelligence into Validated Security
Learn More
Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More

Malicious Telegram Installer Drops Purple Fox Rootkit

January 4, 2022

This AutoIt script is the first stage of the attack which creates a new folder named "TextInputh" under C:UsersUsernameAppDataLocalTemp and drops a legitimate Telegram installer (which is not even executed) and a malicious downloader (TextInputh.exe). When executed, TextInputh.exe creates a new folder named "1640618495" under the C:UsersPublicVideos directory. TextInputh.exe file is used as a downloader for the next stage of the attack. It contacts a C&C server and downloads two files to the newly created folder: 1.rar - which contains the files for the next stage. 7zz.exe - a legitimate 7z archiver. 2.The 7zz.exe is used to unarchive 1.rar, which contains the following files. Next, TextInputh.exe performs the following actions: Copies 360.tct with "360.dll" name, rundll3222.exe and svchost.txt to the ProgramData folder Executes ojbk.exe with the "ojbk.exe -a" command line Deletes 1.rar and 7zz.exe and exits the process ojbk.exe When executed with the "-a" argument, this file is only used to reflectively load the malicious 360.dll file. This DLL is responsible for reading the dropped svchost.txt file. After which, a new HKEY_LOCAL_MACHINESYSTEMSelectMarkTime registry key is created, whose value equals the current time of svchost.exe and then, the svchost.txt payload is executed. As the attack flow continues, this file appears to contain the byte code of the next stage of the malicious payload executed by the 360.dll. As the first action of svchost.txt, it checks for the existence of the HKLMSOFTWAREMicrosoftWindowsCurrentVersionApp Paths360safe.exePath registry key. If the registry key is found, the attack flow will perform an additional step before moving on to the next stage: The attack drops five more files into the ProgramData folder: -Calldriver.exe - this file is used to shut down and block initiation of 360 AV -Driver.sys - after this file is dropped, a new system driver service named "Driver" is created and started on the infected PC and bmd.txt is created in the ProgramData folder. -dll.dll - executed after UAC bypass. The UAC bypass technique used by svchost.txt is a "UAC bypass using CMSTPLUA COM interface" and is well described here. This technique is commonly used by the LockBit and BlackMatter ransomware authors. The dll.dll is executed with the "C:ProgramDatadll.dll, luohua" command line. -kill.bat - a batch script which is executed after the file drop ends. -speedmem2.hg - SQLite file All these files work together to shut down and block the initiation of 360 AV processes from the kernel space, thus allowing the next stage attack tools (Purple Fox Rootkit, in our case) to run without being detected. After the file drop and execution, the payload moves to the next step, which is the C&C communication. As mentioned above, if the HKLMSOFTWAREMicrosoftWindowsCurrentVersionApp Paths360safe.exePath registry key is not found, the flow just skips to this step. First, the hardcoded C&C address is added as a mutex. Next, the following victim's information is gathered: Hostname CPU - by retrieving a value of HKLMHARDWAREDESCRIPTIONSystemCentralProcessor ~MHz registry key Memory status Drive Type Processor Type - by calling GetNativeSystemInfo and checking the value of wProcessorArchitecture. Next, the malware checks if any of the following processes are running on the victim's PC: 360tray.exe - 360 Total Security 360sd.exe - 360 Total Security kxetray.exe - Kingsoft Internet Security KSafeTray.exe - Kingsoft Internet Security QQPCRTP.exe - Tencent HipsTray.exe - HeroBravo System Diagnostics BaiduSd.exe - Baidu Anti-Virus baiduSafeTray.exe - Baidu Anti-Virus KvMonXP.exe - Jiangmin Anti-Virus RavMonD.exe - Rising Anti-Virus QUHLPSVC.EXE - Quick Heal Anti-Virus mssecess.exe - Microsoft MSE cfp.exe - COMODO Internet Security SPIDer.exe acs.exe V3Svc.exe - AhnLab V3 Internet Security AYAgent.aye - ALYac Software avgwdsvc.exe - AVG Internet Security f-secure.exe - F‑Secure Anti‑Virus avp.exe - Kaspersky Anti-Virus Mcshield.exe - McAfee Anti-Virus egui.exe - ESET Smart Security knsdtray.exe TMBMSRV.exe - Trend Micro Internet Security avcenter.exe - Avira Anti-Virus ashDisp.exe - Avast Anti-Virus rtvscan.exe - Symantec Anti-Virus remupd.exe - Panda software vsserv.exe - Bitdefender Total Security PSafeSysTray.exe - PSafe System Tray ad-watch.exe K7TSecurity.exe - K7Security Suite UnThreat.exe - UnThreat Anti-Virus It seems that after this check is complete, all the collected information, including which security products are running, is sent to the C&C server. The last stage of this attack is the download and execution of the Purple Fox Rootkit. Purple Fox uses the msi.dll function, 'MsiInstallProductA', to download and execute its payload. The payload is a .msi file that contains encrypted shellcode including 32-bit and 64-bit versions. Once executed, the system will be restarted with the 'PendingFileRenameOperations' registry to rename its components. In our case the Purple Fox Rootkit is downloaded from hxxp://144.48.243[.]79:17674/C558B828.Png. Calldriver.exe Used to shut down and block initiation of 360 AV processes from the kernel space.