New CleverSoar Malware Attacking Windows Users Bypassing Security Mechanisms
ID: 0ec5d26d-ea67-555f-8a05-01dd5b8ca8e8
STIX ID: report--0ec5d26d-ea67-555f-8a05-01dd5b8ca8e8
Feed Name: GBHackers
CleverSoar is a targeted malware installer (first seen on VirusTotal July 2024, distributed from November 2024) that uses fake .msi packages to infect systems in China and Vietnam, terminating installation on non-Chinese/Vietnamese systems. The installer escalates privileges, loads a rootkit (Nidhogg), deploys a Winos4.0 C2 implant and custom backdoor, disables security controls, employs anti-analysis and virtualization checks, establishes persistence via a service and malicious driver, and shows similarities to the ValleyRAT campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
