logo

ViperSoftX Malware Disguises as eBooks on Torrents to Spread Stealthy Attacks

ID: 3f07b9c1-d676-56fc-8206-5953ae7f40ff

STIX ID: report--3f07b9c1-d676-56fc-8206-5953ae7f40ff

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-07-10

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

ViperSoftX, an information-stealing malware first observed in 2020, is being distributed via malicious eBook RAR archives on torrent sites; the campaign uses deceptive Windows shortcut lures that trigger a multi-stage chain (AutoIt → .NET CLR → PowerShell) to decrypt and execute the stealer. The variant exploits AutoIt UDFs to host PowerShell, patches AMSI, employs anti-analysis and persistence techniques, harvests system data, cryptocurrency wallets, and clipboard contents, and can download additional payloads such as Quasar RAT and TesseractStealer.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.