logo

ViperSoftX Malware Abuses CLR & AutoIt to Execute Malicious Functions & Evade Detection

ID: ed78561a-acfc-515a-b338-ac53a7ed2079

STIX ID: report--ed78561a-acfc-515a-b338-ac53a7ed2079

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2024-07-12

Date Updated: 2026-04-19

Author: Kaaviya

...
...

ViperSoftX is a sophisticated malware family distributed through malicious eBook torrents that uses AutoIt with .NET CLR to run heavily obfuscated PowerShell, achieve persistence via scheduled tasks, patch AMSI to evade detection, and exfiltrate sensitive data (including cryptocurrency wallet information) to a command-and-control server; the report outlines the infection flow, concealed payloads, and evasion techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.