* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Saturday, January 31, 2026
Earth-News
  • Home
  • Business
  • Entertainment

    Local Students Shine Bright, Win Prestigious National Theater Award at 2026 JTF Atlanta

    Sundance Film Festival to name 2026 award winners – LancasterOnline

    Unforgettable Adventures Await in Texarkana This Weekend: January 30 & 31

    AMC Entertainment Gains New Debt Refinancing Flexibility and Reveals Preliminary Q4 and Full Year 2025 Results

    Live Nation, DF Entertainment, and Dale Play Live Join Forces for Long-Term Partnership with Club Atlético River Plate at Mâs Monumental Stadium

    O’Dowd, Dolphin Entertainment CEO, buys $4.9k in DLPN stock – Investing.com

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Pentagon CTO Appoints Six Defense Tech Veterans to Drive Breakthrough Innovations

    How Technology and Consumer Trends Are Set to Revolutionize Hospitality in 2025

    David Simpson Joins Technology Council to Propel Innovation at Drax Technology

    The Next Frontier of AI: Unveiling Technology, Infrastructure, and Policy Trends for 2025-2026

    Expanding advanced heart rhythm care with updated technology – news.llu.edu

    Columbus School Launches Innovative Music Technology Program

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment

    Local Students Shine Bright, Win Prestigious National Theater Award at 2026 JTF Atlanta

    Sundance Film Festival to name 2026 award winners – LancasterOnline

    Unforgettable Adventures Await in Texarkana This Weekend: January 30 & 31

    AMC Entertainment Gains New Debt Refinancing Flexibility and Reveals Preliminary Q4 and Full Year 2025 Results

    Live Nation, DF Entertainment, and Dale Play Live Join Forces for Long-Term Partnership with Club Atlético River Plate at Mâs Monumental Stadium

    O’Dowd, Dolphin Entertainment CEO, buys $4.9k in DLPN stock – Investing.com

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Pentagon CTO Appoints Six Defense Tech Veterans to Drive Breakthrough Innovations

    How Technology and Consumer Trends Are Set to Revolutionize Hospitality in 2025

    David Simpson Joins Technology Council to Propel Innovation at Drax Technology

    The Next Frontier of AI: Unveiling Technology, Infrastructure, and Policy Trends for 2025-2026

    Expanding advanced heart rhythm care with updated technology – news.llu.edu

    Columbus School Launches Innovative Music Technology Program

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

ViperSoftX malware covertly runs PowerShell using AutoIT scripting

July 11, 2024
in Technology
ViperSoftX malware covertly runs PowerShell using AutoIT scripting
Share on FacebookShare on Twitter

ViperSoftX malware covertly runs PowerShell using AutoIT scripting

The latest variants of the ViperSoftX info-stealing malware use the common language runtime (CLR) to load and execute PowerShell commands within AutoIt scripts to evade detection.

CLR is a key component of Microsoft’s .NET Framework, serving as the execution engine and runtime environment for .NET applications.

ViperSoftX uses CLR to load code within AutoIt, a scripting language for automating Windows tasks that are typically trusted by security solutions.

In addition, researchers found that the developer of the malware incorporated modified offensive scripts in the latest versions to increase sophistication.

Infection chain

ViperSoftX has been around since at least 2020 and it is currently distributed on torrent sites as ebooks that deliver malicious RAR archives with a decoy PDF or ebook file, a shortcut (.LNK) file, and PowerShell and AutoIT scripts disguised as JPG image files.

Files in the RAR archiveFiles in the RAR archive
Source: Trellix

Malware researchers at cybersecurity company Trellix say that the infection starts when victims execute the .LNK file. During the process, it loads the PowerShell script that hides within blank spaces commands that are automatically executed in the Command Prompt.

The PS script moves to the %APPDATA%MicrosoftWindows directory two files (zz1Cover2.jpg and zz1Cover3.jpg). One of them is the executable for AutoIt and renamed AutoIt3.exe.

To maintain persistence, the same script configures the Task Scheduler to run AutoIt3.exe every five minutes after the user logs in.

Scheduled tasks added by ViperSoftXScheduled tasks added by ViperSoftX
Source: Trellix

Stealthy operation

By using CLR to load and execute PowerShell commands within the AutoIt environment, ViperSoftX seeks to blend into legitimate activities on the system and evade detection.

This is possible because despite AutoIT not supporting .NET CLR natively, users can define functions that allow invoking PowerShell commands indirectly.

ViperSoftX uses heavy Base64 obfuscation and AES encryption to hide the commands in the PowerShell scripts taken from the image decoy files.

The malware also includes a function to modify the memory of the Antimalware Scan Interface (AMSI) function (‘AmsiScanBuffer’) to bypass security checks on the scripts.

ViperSoftX attack flowViperSoftX attack flow
Source: Trellix

For network communication, ViperSoftX uses deceptive hostnames like ‘security-microsoft.com. To stay under the radar, system information is encoded in the Base64 format and the data is delivered via a POST request with a content length of “0.” In doing so, the threat actor again tries to avoid attention due to the lack of body content.

The objective of ViperSoftX is to steal the following data from compromised systems:

System and hardware details
Cryptocurrency wallet data from browser extensions like MetaMask, Ronin Wallet, and many others
Clipboard contents

ViperSoftX checking the browser extensionsViperSoftX checking the browser extensions
Source: Trellix

Trellix says that ViperSoftX has refined its evasion tactics and has become a bigger threat. By integrating CLR to execute PowerShell inside AutoIt, the malware manages to run malicious functions while evading security mechanisms that typically catch standalone PowerShell activity.

The researchers describe the malware as a sophisticated and agile modern threat that can be thwarted with “a comprehensive defense strategy that encompasses detection, prevention, and response capabilities.”

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting/

Tags: malwaretechnologyViperSoftX
Previous Post

CISA urges devs to weed out OS command injection vulnerabilities

Next Post

GitLab: Critical bug lets attackers run pipelines as other users

Human Guinea Worm Cases Near Extinction with Only 10 Reported Last Year

January 31, 2026

Why a Grand ‘Mar-a-Lago Accord’ for Global Currencies Remains Out of Reach

January 31, 2026

Local Students Shine Bright, Win Prestigious National Theater Award at 2026 JTF Atlanta

January 31, 2026

The Hidden Health Consequences of a Year of Neglect

January 31, 2026

Everything You Need to Know About the Texas 18th District Special Election Runoff

January 31, 2026

Discover the Surprising Forces Driving the Evolution of Gut Microbiomes

January 31, 2026

New Date Announced for the Exciting ACPS Science and Engineering Fair!

January 31, 2026

The Science Behind a Great Guacamole – University of California, Riverside

January 31, 2026

Why Staying Up Late Might Put Your Heart Health at Risk

January 31, 2026

Pentagon CTO Appoints Six Defense Tech Veterans to Drive Breakthrough Innovations

January 31, 2026

Categories

Archives

January 2026
M T W T F S S
 1234
567891011
12131415161718
19202122232425
262728293031  
« Dec    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (1,049)
  • Economy (1,066)
  • Entertainment (21,945)
  • General (19,638)
  • Health (10,108)
  • Lifestyle (1,081)
  • News (22,149)
  • People (1,075)
  • Politics (1,083)
  • Science (16,283)
  • Sports (21,568)
  • Technology (16,049)
  • World (1,058)

Recent News

Human Guinea Worm Cases Near Extinction with Only 10 Reported Last Year

January 31, 2026

Why a Grand ‘Mar-a-Lago Accord’ for Global Currencies Remains Out of Reach

January 31, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version