logo

Multi-Stage VOID#GEIST Malware Delivering XWorm, AsyncRAT, and Xeno RAT

ID: c3723499-e5c8-5d60-b97e-702e12215ea9

STIX ID: report--c3723499-e5c8-5d60-b97e-702e12215ea9

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2026-03-06

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Securonix Threat Research disclosed a stealthy multi-stage campaign dubbed VOID#GEIST that uses obfuscated batch scripts to stage a legitimate embedded Python runtime, decrypt encrypted shellcode modules, and execute multiple RAT payloads (XWorm, Xeno RAT, AsyncRAT) via Early Bird APC injection into explorer.exe; delivery is via phishing and TryCloudflare-hosted ZIPs, persistence is achieved through a user Startup batch, and the framework communicates minimal HTTP beacons to attacker-controlled C2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.