logo

ViperSoftX variant spotted abusing .NET runtime to disguise data theft

ID: fb228fbe-4bac-55e3-830f-9aa234e9cde0

STIX ID: report--fb228fbe-4bac-55e3-830f-9aa234e9cde0

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-07-10

Date Updated: 2026-04-26

Author: Brandon Vigliarolo

...
...

ViperSoftX, a rapidly evolving infostealer, has reemerged with enhanced obfuscation by leveraging the .NET CLR and AutoIt to hide and execute PowerShell payloads; Trellix's analysis shows the malware buries commands in fake JPGs, installs AutoIt and PowerShell scripts, creates scheduled tasks to persist and disable AMSI, and aims to steal system information and cryptocurrency wallets—samples were found bundled with a pirated Excel eBook distributed via torrents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.