Threat Advisory

ViperSoftX Malware Disguised as eBooks Using CLR for PowerShell Execution

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

ViperSoftX has emerged as a highly malware adept at infiltrating systems and exfiltrating sensitive information. This malware has evolved through several iterations, each demonstrating increased complexity and advanced capabilities. Initially spreading through cracked software and torrents, ViperSoftX has now been observed distributing malicious eBooks via torrent links, exploiting users seeking free content.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

ViperSoftX has emerged as a highly malware adept at infiltrating systems and exfiltrating sensitive information. This malware has evolved through several iterations, each demonstrating increased complexity and advanced capabilities. Initially spreading through cracked software and torrents, ViperSoftX has now been observed distributing malicious eBooks via torrent links, exploiting users seeking free content.[emaillocker id="1283"]

The variant of ViperSoftX uses the Common Language Runtime to dynamically load and execute PowerShell commands within the AutoIt environment. This integration enables seamless execution of malicious functions while evading detection mechanisms that would typically flag standalone PowerShell activity. The malware spreads through malicious eBook torrents, concealing its payload in RAR files containing disguised PowerShell scripts, AutoIt scripts, and shortcut files. Upon execution, these scripts unhide hidden folders, configure Windows Task Scheduler, and perform various malicious actions, including scanning for cryptocurrency wallets, gathering system information, and sending data to a Command and Control (C2) server. Additionally, ViperSoftX employs techniques to bypass the Antimalware Scan Interface (AMSI) and uses a combination of reverse base64 and AES encryption to obscure its payloads.

ViperSoftX represents it due to its advanced evasion techniques and multifaceted capabilities. By integrating PowerShell within the AutoIt environment and leveraging CLR, it executes malicious functions seamlessly while bypassing traditional security measures. Its ability to patch AMSI and use encryption for payloads further complicates detection and mitigation efforts. Understanding the operational methods of ViperSoftX and implementing comprehensive defense strategies are crucial for organizations to effectively mitigate the risks posed by this malware, ensuring the security of their digital assets and the integrity of their systems and networks.

THREAT PROFILE:

Tactic Technique Id Technique
 Initial Access T1189 Drive-by Compromise
Execution T1059 Command and Scripting Interpreter
 T1204 User Execution
T1047 Windows Management Instrumentation
T1053 Scheduled Task/Job
Defense Evasion T1140 Deobfuscate/Decode Files or Information
T1564 Hide Artifacts
 T1070 Indicator Removal
 T1036 Masquerading
 T1027 Obfuscated Files or Information
T1562 Impair Defenses
Discovery T1518 Software Discovery
T1087 Account Discovery
T1217 Browser Information Discovery
T1083 File and Directory Discovery
T1033 System Owner/User Discovery
 Collection T1005 Data from Local System
T1115 Clipboard Data
Command and Control T1071 Application Layer Protocol
T1573 Encrypted Channel
T1132 Data Encoding

REFERENCES:

The following reports contain further technical details:

https://thehackernews.com/2024/07/vipersoftx-malware-disguises-as-ebooks.html

[/emaillocker]
crossmenu