Saturday, September 12, 2026

ViperSoftX Malware Used by Threat Actors to Steal Sensitive Information

The AhnLab Security Intelligence Center (ASEC) has recently issued a detailed report confirming the persistent distribution of ViperSoftX malware by threat actors, with notable impact on users in South Korea and beyond.

First identified by Fortinet in 2020, ViperSoftX is a sophisticated PowerShell-based malware designed to infiltrate infected systems, execute remote commands, and steal sensitive data, particularly targeting cryptocurrency-related information.

Ongoing Threat Targets Cryptocurrency Users Globally

Disguised as cracked software, key generators, or even eBooks on torrent sites, as reported by Avast (2022), Trend Micro (2023), and Trellix (2024), this malware employs deceptive initial access tactics to ensnare unsuspecting victims worldwide.

The use of such illegal duplication programs as an infection vector remains a prevalent strategy among various cybercriminals, amplifying the reach of ViperSoftX and resulting in widespread infections.

ViperSoftX demonstrates remarkable persistence through the abuse of Windows Task Scheduler to execute malicious PowerShell scripts periodically.

ViperSoftX Malware
PowerShell downloader

These scripts, often obfuscated or Base64-encrypted, are concealed within files disguised as logs or stored in registry keys like “HKLM\SOFTWARE\HPgs6ZtP670 / xr417LXh,” acting as downloaders for additional payloads.

These downloaders fetch further malware from command-and-control (C&C) servers using techniques like DNS TXT record queries to dynamically crafted domains.

Once deployed, ViperSoftX communicates with its C&C server via HTTP headers such as “X-User-Agent” and “X-notify,” transmitting detailed system information including computer name, Windows version, and installed antivirus data.

Payload Delivery Mechanisms

Beyond data exfiltration, it monitors clipboard activity to steal BIP39 recovery phrases and cryptocurrency wallet addresses for coins like BTC, ETH, and SOL, while also employing a clipboard protection mechanism to thwart competing ClipBanker malware by terminating suspicious processes.

Additionally, ViperSoftX targets browser extensions and installed programs on platforms like Chrome, Firefox, and Edge, relaying this information to threat actors for further exploitation.

Its capabilities extend to executing commands, downloading executables, and even self-removal to evade detection.

The malware’s arsenal includes secondary payloads like Quasar RAT, an open-source remote access Trojan developed in .NET, alongside commercial tools such as PureCrypter, a packer for additional payload delivery, and PureHVNC, a remote control malware.

ViperSoftX Malware
PureHVNC

These tools enable comprehensive control over infected systems, keylogging, and credential theft.

Moreover, ViperSoftX often deploys ClipBanker, which hijacks cryptocurrency wallet addresses from the clipboard, replacing them with attacker-controlled ones during transactions a tactic exploiting the complexity and randomness of wallet addresses that users typically copy and paste.

ASEC warns that an infection can lead to total system compromise, allowing attackers to extract not only cryptocurrency data but also a wide array of user information.

To mitigate risks, users are urged to avoid downloading software from unverified or suspicious sources, apply the latest security patches, and maintain up-to-date antivirus solutions like V3 products to block known attack vectors.

Indicators of Compromise (IOCs)

TypeValue
MD5064b1e45016e8a49eba01878e41ecc37
0ed2d0579b60d9e923b439d8e74b53e1
0efe1a5d5f4066b7e9755ad89ee9470c
197ff9252dd5273e3e77ee07b37fd4dd
1ec4b69f3194bd647639e6b0fa5c7bb5
URLhttp://136.243.132.112/ut.exe
http://136.243.132.112:881/3.exe
http://136.243.132.112:881/APPDATA.exe
http://136.243.132.112:881/a.ps1
http://136.243.132.112:881/firefoxtemp.exe
IP136.243.132.112
160.191.77.89
185.245.183.74
212.56.35.232
89.117.79.31

To Upgrade Your Cybersecurity Skills, Take Diamond Membership With 150+ Practical Cybersecurity Courses Online – Enroll Here

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News