ViperSoftX malware covertly runs PowerShell using AutoIT scripting
ID: 29e42ed9-d141-5e0b-9e80-123458e7a245
STIX ID: report--29e42ed9-d141-5e0b-9e80-123458e7a245
Feed Name: Bleeping Computer
Threat Score
ViperSoftX is an info-stealing malware distributed via malicious RAR archives on torrent sites; it uses a crafted .LNK to run obfuscated PowerShell and AutoIt binaries, leverages the .NET CLR inside AutoIt to execute hidden PowerShell payloads, bypasses AMSI, maintains persistence through scheduled tasks, and exfiltrates system information, clipboard contents and cryptocurrency wallet data to deceptive C2 hostnames.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
