ViperSoftX Malware Spreads Through Cracked Software, Targeting Unsuspecting Users

AhnLab Security Intelligence Center (ASEC) recently uncovered a sophisticated malware campaign involving ViperSoftX, targeting South Korean victims.

ViperSoftX, a malicious PowerShell-based malware, is primarily distributed under the guise of cracked software or torrents, disguised as legitimate programs.

While the initial distribution method remains unclear, analysis of the malware’s code has revealed Arabic comments, strongly suggesting its operators are Arabic-speaking attackers.

ViperSoftX serves as the initial stage in this multi-layered attack, communicating with command-and-control (C&C) servers and downloading additional malware to compromise victim systems further.

The attackers use specific URI paths, such as “/api/”, “/api/v1”, “/api/v2”, and “/api/v3/”, in their C&C communication processes.

Among the downloaded malware, tools like VBS downloader scripts, PowerShell scripts, PureCrypter packers, and the Quasar RAT remote access tool have been identified, each playing a distinct role in the attack chain.

ViperSoftX Malware
VBS downloader

VBS and PowerShell Scripts: Evading Detection and Securing Access

Key components of the attack include the VBS downloader and an accompanying PowerShell script.

The VBS file, titled “vbs.vbs,” is used to download and execute additional malicious files, storing them in a designated folder, “C:\ProgramData\SystemLoader.”

This script also ensures the execution of “run.vbs” if present, which acts as a runner to execute a PowerShell script (“a.ps1”).

ViperSoftX Malware
 PowerShell script code

The Arabic comments within the code provide insights into its functionality, such as downloading files, executing scripts, and ensuring persistence.

The PowerShell script “a.ps1” escalates the attack by bypassing Windows Defender, securing administrator privileges, and executing additional payloads downloaded from remote servers.

It employs TLS 1.2 protocol while ignoring server certificate validation to establish reliable communication channels.

Furthermore, the script adds exception paths to Windows Defender in common directories (C:\, D:$$ to evade detection, ensuring the malware operates uninterrupted.

Notably, this script creates and executes a malicious file named “NVIDIA.exe” within the “C:\ProgramData” directory.

PureCrypter and Quasar RAT: Advanced Payloads for C&C Communication and Remote Control

Among the malware distributed by ViperSoftX, PureCrypter plays a crucial role as a downloader.

PureCrypter, a commercial .NET packer, has been widely used by threat actors since 2021 to deploy various malicious payloads.

It leverages the Protobuf library for serialized communication and uses predefined message structures to interact with C&C servers.

PureCrypter was found to drop files in paths such as “%ALLUSERSPROFILE%\nvidia.exe” and “%ALLUSERSPROFILE%\teamviewer.exe,” pointing to its versatile features in facilitating broader attacks.

In addition to PureCrypter, the attackers use Quasar RAT, an open-source remote access tool built on .NET.

Quasar RAT enables attackers to execute remote commands, engage in keylogging, and transfer files, offering them extensive control over compromised systems.

It is suspected that the RAT aids in maintaining persistent access and extracting sensitive information from infected systems.

ASEC’s analysis has identified critical indicators of compromise (IoCs), including malicious file hashes and C&C IP addresses such as 89.117.79[.]31, 65.109.29[.]234, and 136[.]243[.]132[.]112.

The ongoing campaign demonstrates the adaptability of the threat actors, with potential for additional malware variants to be distributed in future attacks.

To mitigate the risk of infection, users are advised against downloading software from torrent sites or using cracked programs, as these are common distribution channels for ViperSoftX.

Instead, legitimate software sources should be utilized, and antivirus solutions must be updated regularly to detect and block emerging threats.

AhnLab continues to monitor this attack with its advanced threat intelligence platform to protect users from further exploitation.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories