ViperSoftX variant spotted abusing .NET runtime to disguise data theft
ID: fb228fbe-4bac-55e3-830f-9aa234e9cde0
STIX ID: report--fb228fbe-4bac-55e3-830f-9aa234e9cde0
Feed Name: The Register (Security)
Threat Score
ViperSoftX, a rapidly evolving infostealer, has reemerged with enhanced obfuscation by leveraging the .NET CLR and AutoIt to hide and execute PowerShell payloads; Trellix's analysis shows the malware buries commands in fake JPGs, installs AutoIt and PowerShell scripts, creates scheduled tasks to persist and disable AMSI, and aims to steal system information and cryptocurrency wallets—samples were found bundled with a pirated Excel eBook distributed via torrents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
