ViperSoftX is a financially motivated cybercrime operation centered on a Windows malware family used for remote control, cryptocurrency theft, and follow-on payload delivery. First publicly identified in 2020, the activity has evolved from JavaScript-based delivery to PowerShell-heavy tradecraft and has expanded beyond clipboard hijacking into broader post-compromise tooling, including coin-mining and additional remote-access malware. ViperSoftX is commonly distributed through trojanized software cracks, key generators, and pirated eBooks, including torrent-delivered lures. On infected systems it establishes persistence through scheduled tasks that periodically launch malicious PowerShell. The malware can decrypt embedded payload data, execute commands stored in the registry, download and run additional payloads, collect host information, and remove or restart itself. Command and control has included domain-generation techniques and abuse of DNS TXT records. The operation is strongly associated with cryptocurrency-focused theft. ViperSoftX monitors clipboard contents to replace wallet addresses, watches for cryptocurrency wallet applications, and checks for browser extensions and password managers including KeePass and 1Password. Related activity has also involved VenomSoftX, a malicious browser extension used for information theft. Operators linked to ViperSoftX have deployed additional tooling including QuasarRAT, PureRAT (PureHVNC), and ClipBanker. These tools extend the actor’s capabilities with remote administration, file and process management, registry interaction, remote command execution, keylogging, clipboard theft, and hidden virtual network computing functionality. Reporting in 2025 also tied the operation to downloader activity consistent with PureLogs deployment and to Monero coin-mining through configurations associated with XMRig. Victimology is global, with notable infection volume observed in South Korea. The actor’s behavior is consistent with cybercriminal monetization through cryptocurrency theft and illicit mining rather than espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.