HomeSecurityHackers distribute ViperSoftX malware via cracked software

Hackers distribute ViperSoftX malware via cracked software

AhnLab Security Intelligence Center (ASEC) has revealed that hackers (most likely Arabic-speaking) are distributing the ViperSoftX malwarethrough cracked software and torrents. The main targets are Korean users.

Hackers distribute ViperSoftX malware via cracked software

Arabic comments found in PowerShell and VBS scripts used for Command and Control (C&C) communicationsuggest that the attackers are fluent in Arabic.

ViperSoftX is a dangerous malware that is often disguised as legitimate software, tricking users into downloading and installing it via fake programs or bundled with other software in torrents.

See also: Authorities arrested customers of Smokeloader malware

Secondary malware payloads

After the initial infection with ViperSoftX, the attack evolves as the PowerShell downloader retrieves two sophisticated malware payloads: PureCrypter and Quasar RAT.

PureCrypter, a commercial .NET packer sold on underground forums since 2021, leverages Protocol Buffers (ProtoBuf) library for covert C&C communications. It creates multiple executables in the %ALLUSERSPROFILE% with names like “nvidia.exe” and “teamviewer.exe” to make them appear legitimate.

The final payload, the Quasar RAT, is a remote access tool that provides attackers with comprehensive control over the compromised device (e.g. keystroke logging, remote command execution, and file transfer).

See also: Fake Microsoft Office add-ins push malware via SourceForge

Quasar creates persistence with file names like “winrar.exe” and “micro.exe” to evade detection by impersonating legitimate software.

“This campaign demonstrates sophisticated techniques for bypassing security checks and maintaining persistence,” ASEC researchers noted. “The use of multiple scripting stages and commercial malware tools suggests a threat actor with considerable resources.”

Command and Control Infrastructure

According to researchers, the attackers use various IP addresses for communication and control:

IP addresses:

89.117.79.31: Used for initial communication, observed with ports 56005, 56004 and 56003.
65.109.29.234: Observed with port 7702 for communication with Quasar RAT.

ViperSoftX malware cracked software hackers
Hackers distribute ViperSoftX malware via cracked software

Indicators of Compromise (IoCs)

Several indicators of violation (IoC) have been created for this campaign:

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

• MD5 Hashes:

o 05cbfc994e6f084f536cdcf3f93e476f
o 4c6daef71ae1db6c6e790fca5974f1ca
o 70e51709238385fd30ab427eb82e0836
o 7d937e196962e3ebbbdee6d3a002f0cf
or e5d6c58d17ebce8b0e7e089dfc60ff1a

• IP Addresses:

o 136.243.132.112: Possible C&C address
o 65.109.29.234: C&C for the Quasar RAT
o 89.117.79.31: Main C&C address

Monitoring these IPs and hashes allows for immediate detection and blocking of the malicious campaign at various stages.

See also: ESET vulnerability exploited to secretly execute malware

Users should be cautious when installing files downloaded from dubious sources and avoid pirated/cracked software.

In general, to protect yourself from such risks (ViperSoftX infection and other malware), the most reliable approach is to download software only from certified sources. Torrents, cracks, and other software that you can find on the Internet are usually infected with malware and viruses. In addition, security measures such as installing a firewall, using an antivirus, and multi-factor authentication will keep devices safe.

Source: gbhackers.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS