* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Sunday, May 18, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    We won’t get a Game of Thrones show this year: A Knight of the Seven Kingdoms shifts to early 2026 – Entertainment Weekly

    Game of Thrones Fans Will Have to Wait: A Knight of the Seven Kingdoms Delayed Until 2026!

    Nile Entertainment Secures African Rights for Thrilling Action Film ‘Son of the Soil

    Florida Highwaymen movie ‘Legends of the Highway’ based on original 26 Black artists – Treasure Coast News

    Unveiling ‘Legends of the Highway’: A Captivating Film Celebrating the Legacy of Florida’s Original 26 Black Artists

    Alabama to expand Entertainment Industry Incentive Act – WVTM

    Alabama Boosts Entertainment Industry with Expanded Incentive Act!

    Toast Sets Its Sights on Revolutionizing Entertainment Venues

    Eva Dickerman Joins Entertainment 360 As Partner – Deadline

    Eva Dickerman Takes the Spotlight as New Partner at Entertainment 360!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Super Speeders are deadly. This technology can slow them down. – Popular Science

    Revolutionary Technology: Taming the Threat of Super Speeders!

    Celebrating Success: Highlights from the Collaborative College for Technology & Leadership Graduation Ceremony

    Philly police unveil strategy to crack down on car meetups utilizing technology – NBC10 Philadelphia

    Philly Police Launch High-Tech Strategy to Tackle Car Meetups!

    Stony Brook Medicine Pioneers Use of AI Technology for Heart Disease Diagnosis on Long Island – SBU News

    Revolutionizing Heart Health: Stony Brook Medicine Leads the Way with AI Technology

    How to Clean Up and Restore Low-Quality Videos with AI Technology – finehomesandliving.com

    How to Clean Up and Restore Low-Quality Videos with AI Technology – finehomesandliving.com

    Opening kids’ eyes to the wonders of Information and Communication Technology at EBU Girls in ICT Day 2025 – EBU tech

    Unleashing Curiosity: Exploring the Magic of Information and Communication Technology at EBU Girls in ICT Day 2025!

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    We won’t get a Game of Thrones show this year: A Knight of the Seven Kingdoms shifts to early 2026 – Entertainment Weekly

    Game of Thrones Fans Will Have to Wait: A Knight of the Seven Kingdoms Delayed Until 2026!

    Nile Entertainment Secures African Rights for Thrilling Action Film ‘Son of the Soil

    Florida Highwaymen movie ‘Legends of the Highway’ based on original 26 Black artists – Treasure Coast News

    Unveiling ‘Legends of the Highway’: A Captivating Film Celebrating the Legacy of Florida’s Original 26 Black Artists

    Alabama to expand Entertainment Industry Incentive Act – WVTM

    Alabama Boosts Entertainment Industry with Expanded Incentive Act!

    Toast Sets Its Sights on Revolutionizing Entertainment Venues

    Eva Dickerman Joins Entertainment 360 As Partner – Deadline

    Eva Dickerman Takes the Spotlight as New Partner at Entertainment 360!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Super Speeders are deadly. This technology can slow them down. – Popular Science

    Revolutionary Technology: Taming the Threat of Super Speeders!

    Celebrating Success: Highlights from the Collaborative College for Technology & Leadership Graduation Ceremony

    Philly police unveil strategy to crack down on car meetups utilizing technology – NBC10 Philadelphia

    Philly Police Launch High-Tech Strategy to Tackle Car Meetups!

    Stony Brook Medicine Pioneers Use of AI Technology for Heart Disease Diagnosis on Long Island – SBU News

    Revolutionizing Heart Health: Stony Brook Medicine Leads the Way with AI Technology

    How to Clean Up and Restore Low-Quality Videos with AI Technology – finehomesandliving.com

    How to Clean Up and Restore Low-Quality Videos with AI Technology – finehomesandliving.com

    Opening kids’ eyes to the wonders of Information and Communication Technology at EBU Girls in ICT Day 2025 – EBU tech

    Unleashing Curiosity: Exploring the Magic of Information and Communication Technology at EBU Girls in ICT Day 2025!

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

ViperSoftX malware covertly runs PowerShell using AutoIT scripting

July 11, 2024
in Technology
ViperSoftX malware covertly runs PowerShell using AutoIT scripting
Share on FacebookShare on Twitter

ViperSoftX malware covertly runs PowerShell using AutoIT scripting

The latest variants of the ViperSoftX info-stealing malware use the common language runtime (CLR) to load and execute PowerShell commands within AutoIt scripts to evade detection.

CLR is a key component of Microsoft’s .NET Framework, serving as the execution engine and runtime environment for .NET applications.

ViperSoftX uses CLR to load code within AutoIt, a scripting language for automating Windows tasks that are typically trusted by security solutions.

In addition, researchers found that the developer of the malware incorporated modified offensive scripts in the latest versions to increase sophistication.

Infection chain

ViperSoftX has been around since at least 2020 and it is currently distributed on torrent sites as ebooks that deliver malicious RAR archives with a decoy PDF or ebook file, a shortcut (.LNK) file, and PowerShell and AutoIT scripts disguised as JPG image files.

Files in the RAR archiveFiles in the RAR archive
Source: Trellix

Malware researchers at cybersecurity company Trellix say that the infection starts when victims execute the .LNK file. During the process, it loads the PowerShell script that hides within blank spaces commands that are automatically executed in the Command Prompt.

The PS script moves to the %APPDATA%MicrosoftWindows directory two files (zz1Cover2.jpg and zz1Cover3.jpg). One of them is the executable for AutoIt and renamed AutoIt3.exe.

To maintain persistence, the same script configures the Task Scheduler to run AutoIt3.exe every five minutes after the user logs in.

Scheduled tasks added by ViperSoftXScheduled tasks added by ViperSoftX
Source: Trellix

Stealthy operation

By using CLR to load and execute PowerShell commands within the AutoIt environment, ViperSoftX seeks to blend into legitimate activities on the system and evade detection.

This is possible because despite AutoIT not supporting .NET CLR natively, users can define functions that allow invoking PowerShell commands indirectly.

ViperSoftX uses heavy Base64 obfuscation and AES encryption to hide the commands in the PowerShell scripts taken from the image decoy files.

The malware also includes a function to modify the memory of the Antimalware Scan Interface (AMSI) function (‘AmsiScanBuffer’) to bypass security checks on the scripts.

ViperSoftX attack flowViperSoftX attack flow
Source: Trellix

For network communication, ViperSoftX uses deceptive hostnames like ‘security-microsoft.com. To stay under the radar, system information is encoded in the Base64 format and the data is delivered via a POST request with a content length of “0.” In doing so, the threat actor again tries to avoid attention due to the lack of body content.

The objective of ViperSoftX is to steal the following data from compromised systems:

System and hardware details
Cryptocurrency wallet data from browser extensions like MetaMask, Ronin Wallet, and many others
Clipboard contents

ViperSoftX checking the browser extensionsViperSoftX checking the browser extensions
Source: Trellix

Trellix says that ViperSoftX has refined its evasion tactics and has become a bigger threat. By integrating CLR to execute PowerShell inside AutoIt, the malware manages to run malicious functions while evading security mechanisms that typically catch standalone PowerShell activity.

The researchers describe the malware as a sophisticated and agile modern threat that can be thwarted with “a comprehensive defense strategy that encompasses detection, prevention, and response capabilities.”

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting/

Tags: malwaretechnologyViperSoftX
Previous Post

CISA urges devs to weed out OS command injection vulnerabilities

Next Post

GitLab: Critical bug lets attackers run pipelines as other users

How ecology, statistics and interdisciplinary collaboration can save species – UCT News

How ecology, statistics and interdisciplinary collaboration can save species – UCT News

May 18, 2025
150,000-year history of Earth’s magnetic field reveals clues about the climate when early humans were spreading out of Africa – Live Science

150,000-year history of Earth’s magnetic field reveals clues about the climate when early humans were spreading out of Africa – Live Science

May 18, 2025
Experimental gene editing helped a desperately ill baby thrive. Scientists say it could someday treat millions – PBS

Revolutionary Gene Editing Gives Hope to Desperate Parents: A Breakthrough for Millions

May 18, 2025
The lifestyle tweaks that gave me a biological age of 20 – at 61! – Daily Mail

How I Reversed My Biological Age to 20 at 61 with Simple Lifestyle Changes!

May 18, 2025
2025 U20 & U23 World Team Trials Wrestling Entries – FloWrestling

2025 U20 & U23 World Team Trials Wrestling Entries – FloWrestling

May 18, 2025
Japan’s economy shrinks more than expected as US tariff hit looms – Reuters

Japan’s Economy Faces Unexpected Contraction Amid Looming US Tariff Threat

May 18, 2025
We won’t get a Game of Thrones show this year: A Knight of the Seven Kingdoms shifts to early 2026 – Entertainment Weekly

Game of Thrones Fans Will Have to Wait: A Knight of the Seven Kingdoms Delayed Until 2026!

May 18, 2025
Apex mayor lead 1,000 men in march for mental health awareness – WRAL.com

Apex mayor lead 1,000 men in march for mental health awareness – WRAL.com

May 18, 2025
Far-right leaders attempting to hijack success of Reform – BBC

Far-Right Leaders Seek to Capitalize on Reform’s Momentum

May 18, 2025
Super Speeders are deadly. This technology can slow them down. – Popular Science

Revolutionary Technology: Taming the Threat of Super Speeders!

May 18, 2025

Categories

Archives

May 2025
MTWTFSS
 1234
567891011
12131415161718
19202122232425
262728293031 
« Apr    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (617)
  • Economy (630)
  • Entertainment (21,544)
  • General (15,223)
  • Health (9,672)
  • Lifestyle (635)
  • News (22,149)
  • People (634)
  • Politics (638)
  • Science (15,854)
  • Sports (21,140)
  • Technology (15,621)
  • World (620)

Recent News

How ecology, statistics and interdisciplinary collaboration can save species – UCT News

How ecology, statistics and interdisciplinary collaboration can save species – UCT News

May 18, 2025
150,000-year history of Earth’s magnetic field reveals clues about the climate when early humans were spreading out of Africa – Live Science

150,000-year history of Earth’s magnetic field reveals clues about the climate when early humans were spreading out of Africa – Live Science

May 18, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version