EXECUTIVE SUMMARY
ViperSoftX has emerged as a highly malware adept at infiltrating systems and exfiltrating sensitive information. This malware has evolved through several iterations, each demonstrating increased complexity and advanced capabilities. Initially spreading through cracked software and torrents, ViperSoftX has now been observed distributing malicious eBooks via torrent links, exploiting users seeking free content.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
ViperSoftX has emerged as a highly malware adept at infiltrating systems and exfiltrating sensitive information. This malware has evolved through several iterations, each demonstrating increased complexity and advanced capabilities. Initially spreading through cracked software and torrents, ViperSoftX has now been observed distributing malicious eBooks via torrent links, exploiting users seeking free content.[emaillocker id="1283"]
The variant of ViperSoftX uses the Common Language Runtime to dynamically load and execute PowerShell commands within the AutoIt environment. This integration enables seamless execution of malicious functions while evading detection mechanisms that would typically flag standalone PowerShell activity. The malware spreads through malicious eBook torrents, concealing its payload in RAR files containing disguised PowerShell scripts, AutoIt scripts, and shortcut files. Upon execution, these scripts unhide hidden folders, configure Windows Task Scheduler, and perform various malicious actions, including scanning for cryptocurrency wallets, gathering system information, and sending data to a Command and Control (C2) server. Additionally, ViperSoftX employs techniques to bypass the Antimalware Scan Interface (AMSI) and uses a combination of reverse base64 and AES encryption to obscure its payloads.
ViperSoftX represents it due to its advanced evasion techniques and multifaceted capabilities. By integrating PowerShell within the AutoIt environment and leveraging CLR, it executes malicious functions seamlessly while bypassing traditional security measures. Its ability to patch AMSI and use encryption for payloads further complicates detection and mitigation efforts. Understanding the operational methods of ViperSoftX and implementing comprehensive defense strategies are crucial for organizations to effectively mitigate the risks posed by this malware, ensuring the security of their digital assets and the integrity of their systems and networks.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1189 | Drive-by Compromise |
| Execution | T1059 | Command and Scripting Interpreter |
| T1204 | User Execution | |
| T1047 | Windows Management Instrumentation | |
| T1053 | Scheduled Task/Job | |
| Defense Evasion | T1140 | Deobfuscate/Decode Files or Information |
| T1564 | Hide Artifacts | |
| T1070 | Indicator Removal | |
| T1036 | Masquerading | |
| T1027 | Obfuscated Files or Information | |
| T1562 | Impair Defenses | |
| Discovery | T1518 | Software Discovery |
| T1087 | Account Discovery | |
| T1217 | Browser Information Discovery | |
| T1083 | File and Directory Discovery | |
| T1033 | System Owner/User Discovery | |
| Collection | T1005 | Data from Local System |
| T1115 | Clipboard Data | |
| Command and Control | T1071 | Application Layer Protocol |
| T1573 | Encrypted Channel | |
| T1132 | Data Encoding |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/07/vipersoftx-malware-disguises-as-ebooks.html
[/emaillocker]