logo

ViperSoftX malware covertly runs PowerShell using AutoIT scripting

ID: 29e42ed9-d141-5e0b-9e80-123458e7a245

STIX ID: report--29e42ed9-d141-5e0b-9e80-123458e7a245

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-07-10

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

ViperSoftX is an info-stealing malware distributed via malicious RAR archives on torrent sites; it uses a crafted .LNK to run obfuscated PowerShell and AutoIt binaries, leverages the .NET CLR inside AutoIt to execute hidden PowerShell payloads, bypasses AMSI, maintains persistence through scheduled tasks, and exfiltrates system information, clipboard contents and cryptocurrency wallet data to deceptive C2 hostnames.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.