AhnLab Security Intelligence Center (ASEC) has revealed that hackers (most likely Arabic-speaking) are distributing the ViperSoftX malwarethrough cracked software and torrents. The main targets are Korean users.

Arabic comments found in PowerShell and VBS scripts used for Command and Control (C&C) communicationsuggest that the attackers are fluent in Arabic.
ViperSoftX is a dangerous malware that is often disguised as legitimate software, tricking users into downloading and installing it via fake programs or bundled with other software in torrents.
See also: Authorities arrested customers of Smokeloader malware
Secondary malware payloads
After the initial infection with ViperSoftX, the attack evolves as the PowerShell downloader retrieves two sophisticated malware payloads: PureCrypter and Quasar RAT.
PureCrypter, a commercial .NET packer sold on underground forums since 2021, leverages Protocol Buffers (ProtoBuf) library for covert C&C communications. It creates multiple executables in the %ALLUSERSPROFILE% with names like “nvidia.exe” and “teamviewer.exe” to make them appear legitimate.
The final payload, the Quasar RAT, is a remote access tool that provides attackers with comprehensive control over the compromised device (e.g. keystroke logging, remote command execution, and file transfer).
See also: Fake Microsoft Office add-ins push malware via SourceForge
Quasar creates persistence with file names like “winrar.exe” and “micro.exe” to evade detection by impersonating legitimate software.
“This campaign demonstrates sophisticated techniques for bypassing security checks and maintaining persistence,” ASEC researchers noted. “The use of multiple scripting stages and commercial malware tools suggests a threat actor with considerable resources.”
Command and Control Infrastructure
According to researchers, the attackers use various IP addresses for communication and control:
IP addresses:
89.117.79.31: Used for initial communication, observed with ports 56005, 56004 and 56003.
65.109.29.234: Observed with port 7702 for communication with Quasar RAT.

Indicators of Compromise (IoCs)
Several indicators of violation (IoC) have been created for this campaign:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
• MD5 Hashes:
o 05cbfc994e6f084f536cdcf3f93e476f
o 4c6daef71ae1db6c6e790fca5974f1ca
o 70e51709238385fd30ab427eb82e0836
o 7d937e196962e3ebbbdee6d3a002f0cf
or e5d6c58d17ebce8b0e7e089dfc60ff1a
• IP Addresses:
o 136.243.132.112: Possible C&C address
o 65.109.29.234: C&C for the Quasar RAT
o 89.117.79.31: Main C&C address
Monitoring these IPs and hashes allows for immediate detection and blocking of the malicious campaign at various stages.
See also: ESET vulnerability exploited to secretly execute malware
Users should be cautious when installing files downloaded from dubious sources and avoid pirated/cracked software.
In general, to protect yourself from such risks (ViperSoftX infection and other malware), the most reliable approach is to download software only from certified sources. Torrents, cracks, and other software that you can find on the Internet are usually infected with malware and viruses. In addition, security measures such as installing a firewall, using an antivirus, and multi-factor authentication will keep devices safe.
Source: gbhackers.com
