logo

New CleverSoar Malware Attacking Windows Users Bypassing Security Mechanisms

ID: 0ec5d26d-ea67-555f-8a05-01dd5b8ca8e8

STIX ID: report--0ec5d26d-ea67-555f-8a05-01dd5b8ca8e8

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2024-12-02

Date Updated: 2026-04-22

Author: Varshini

...
...

CleverSoar is a targeted malware installer (first seen on VirusTotal July 2024, distributed from November 2024) that uses fake .msi packages to infect systems in China and Vietnam, terminating installation on non-Chinese/Vietnamese systems. The installer escalates privileges, loads a rootkit (Nidhogg), deploys a Winos4.0 C2 implant and custom backdoor, disables security controls, employs anti-analysis and virtualization checks, establishes persistence via a service and malicious driver, and shows similarities to the ValleyRAT campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.