ViperSoftX Malware Disguises as eBooks on Torrents to Spread Stealthy Attacks
ID: 3f07b9c1-d676-56fc-8206-5953ae7f40ff
STIX ID: report--3f07b9c1-d676-56fc-8206-5953ae7f40ff
Feed Name: The Hacker News
ViperSoftX, an information-stealing malware first observed in 2020, is being distributed via malicious eBook RAR archives on torrent sites; the campaign uses deceptive Windows shortcut lures that trigger a multi-stage chain (AutoIt → .NET CLR → PowerShell) to decrypt and execute the stealer. The variant exploits AutoIt UDFs to host PowerShell, patches AMSI, employs anti-analysis and persistence techniques, harvests system data, cryptocurrency wallets, and clipboard contents, and can download additional payloads such as Quasar RAT and TesseractStealer.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
