Cyber Security News

ViperSoftX Malware Used by Threat Actors to Steal Sensitive Information

The AhnLab Security Intelligence Center (ASEC) has recently issued a detailed report confirming the persistent distribution of ViperSoftX malware by threat actors, with notable impact on users in South Korea and beyond.

First identified by Fortinet in 2020, ViperSoftX is a sophisticated PowerShell-based malware designed to infiltrate infected systems, execute remote commands, and steal sensitive data, particularly targeting cryptocurrency-related information.

Ongoing Threat Targets Cryptocurrency Users Globally

Disguised as cracked software, key generators, or even eBooks on torrent sites, as reported by Avast (2022), Trend Micro (2023), and Trellix (2024), this malware employs deceptive initial access tactics to ensnare unsuspecting victims worldwide.

The use of such illegal duplication programs as an infection vector remains a prevalent strategy among various cybercriminals, amplifying the reach of ViperSoftX and resulting in widespread infections.

ViperSoftX demonstrates remarkable persistence through the abuse of Windows Task Scheduler to execute malicious PowerShell scripts periodically.

PowerShell downloader

These scripts, often obfuscated or Base64-encrypted, are concealed within files disguised as logs or stored in registry keys like “HKLM\SOFTWARE\HPgs6ZtP670 / xr417LXh,” acting as downloaders for additional payloads.

These downloaders fetch further malware from command-and-control (C&C) servers using techniques like DNS TXT record queries to dynamically crafted domains.

Once deployed, ViperSoftX communicates with its C&C server via HTTP headers such as “X-User-Agent” and “X-notify,” transmitting detailed system information including computer name, Windows version, and installed antivirus data.

Payload Delivery Mechanisms

Beyond data exfiltration, it monitors clipboard activity to steal BIP39 recovery phrases and cryptocurrency wallet addresses for coins like BTC, ETH, and SOL, while also employing a clipboard protection mechanism to thwart competing ClipBanker malware by terminating suspicious processes.

Additionally, ViperSoftX targets browser extensions and installed programs on platforms like Chrome, Firefox, and Edge, relaying this information to threat actors for further exploitation.

Its capabilities extend to executing commands, downloading executables, and even self-removal to evade detection.

The malware’s arsenal includes secondary payloads like Quasar RAT, an open-source remote access Trojan developed in .NET, alongside commercial tools such as PureCrypter, a packer for additional payload delivery, and PureHVNC, a remote control malware.

PureHVNC

These tools enable comprehensive control over infected systems, keylogging, and credential theft.

Moreover, ViperSoftX often deploys ClipBanker, which hijacks cryptocurrency wallet addresses from the clipboard, replacing them with attacker-controlled ones during transactions a tactic exploiting the complexity and randomness of wallet addresses that users typically copy and paste.

ASEC warns that an infection can lead to total system compromise, allowing attackers to extract not only cryptocurrency data but also a wide array of user information.

To mitigate risks, users are urged to avoid downloading software from unverified or suspicious sources, apply the latest security patches, and maintain up-to-date antivirus solutions like V3 products to block known attack vectors.

Indicators of Compromise (IOCs)

TypeValue
MD5064b1e45016e8a49eba01878e41ecc37
0ed2d0579b60d9e923b439d8e74b53e1
0efe1a5d5f4066b7e9755ad89ee9470c
197ff9252dd5273e3e77ee07b37fd4dd
1ec4b69f3194bd647639e6b0fa5c7bb5
URLhttp://136.243.132.112/ut.exe
http://136.243.132.112:881/3.exe
http://136.243.132.112:881/APPDATA.exe
http://136.243.132.112:881/a.ps1
http://136.243.132.112:881/firefoxtemp.exe
IP136.243.132.112
160.191.77.89
185.245.183.74
212.56.35.232
89.117.79.31

To Upgrade Your Cybersecurity Skills, Take Diamond Membership With 150+ Practical Cybersecurity Courses Online – Enroll Here

Aman Mishra

Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Recent Posts

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to automate cyberattacks, accelerate data theft, and…

15 hours ago

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel…

15 hours ago

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate Windows utility mshta.exe to execute malicious…

17 hours ago

OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE

A swarm of AI agents believed to be operated internally by OpenAI uploaded more than…

17 hours ago

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked…

18 hours ago

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to…

1 day ago