ViperSoftX Malware Abuses CLR & AutoIt to Execute Malicious Functions & Evade Detection
ID: ed78561a-acfc-515a-b338-ac53a7ed2079
STIX ID: report--ed78561a-acfc-515a-b338-ac53a7ed2079
Feed Name: Cyber Press
Threat Score
ViperSoftX is a sophisticated malware family distributed through malicious eBook torrents that uses AutoIt with .NET CLR to run heavily obfuscated PowerShell, achieve persistence via scheduled tasks, patch AMSI to evade detection, and exfiltrate sensitive data (including cryptocurrency wallet information) to a command-and-control server; the report outlines the infection flow, concealed payloads, and evasion techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
