ViperSoftX Attackers Target Monero
ID: b2f5f60f-7931-5c22-aab3-2742047aeabc
STIX ID: report--b2f5f60f-7931-5c22-aab3-2742047aeabc
Feed Name: ASEC
This AhnLab/ASEC report analyzes the ViperSoftX threat cluster and related malware (QuasarRAT, PureRAT, ClipBanker), detailing distribution via cracked software and torrents, PowerShell-based loaders, capabilities to steal crypto wallet addresses and credentials (clipboard monitoring, wallet app checks, password manager detection), and recent use of XMRig-based Monero coin miners; the report includes technical analysis, command behavior, configuration screenshots, and multiple IOCs (MD5 hashes, URLs, FQDNs, IPs) with guidance to avoid suspicious downloads and keep systems patched and protected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
