Inside ViperSoftX: Exploiting AutoIt and CLR for Stealthy PowerShell Execution
Threat Level – Red | Attack Report
Download PDFThe sophisticated malware known as ViperSoftX has been observed being distributed as eBooks over torrent networks. The latest variants of the ViperSoftX info-stealing malware employ the Common Language Runtime (CLR) to load and execute PowerShell commands within AutoIt scripts, effectively evading detection. ViperSoftX leverages CLR to load code within AutoIt, a scripting language used for automating Windows tasks that is typically trusted by security solutions. CLR, a key component of Microsoft’s .NET Framework, serves as the execution engine and runtime environment for .NET applications.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox