Multi-Stage VOID#GEIST Malware Delivering XWorm, AsyncRAT, and Xeno RAT
ID: c3723499-e5c8-5d60-b97e-702e12215ea9
STIX ID: report--c3723499-e5c8-5d60-b97e-702e12215ea9
Feed Name: The Hacker News
Securonix Threat Research disclosed a stealthy multi-stage campaign dubbed VOID#GEIST that uses obfuscated batch scripts to stage a legitimate embedded Python runtime, decrypt encrypted shellcode modules, and execute multiple RAT payloads (XWorm, Xeno RAT, AsyncRAT) via Early Bird APC injection into explorer.exe; delivery is via phishing and TryCloudflare-hosted ZIPs, persistence is achieved through a user Startup batch, and the framework communicates minimal HTTP beacons to attacker-controlled C2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
