Developers behind Purple Fox fileless downloader malware targeting two new vulnerabilities. Purple Fox is now exploiting two additional vulnerabilities to gain access to networks. The first, tracked as CVE-2020-0674, is a scripting engine memory corruption vulnerability in Internet Explorer. The second flaw is a local privilege elevation vulnerability in certain versions of Windows. The Purple Fox gang recently built a new exploit kit, given the eponymous name Purple Fox, replacing the RIG exploit kit that it previously used to distribute the malware.”]
Source: https://www.govinfosecurity.com/purple-fox-malware-targets-more-vulnerabilities-a-14574

