ViperSoftX is a long-running Windows information stealer and cryptocurrency-focused malware family that has been actively developed since at least 2020. It is primarily distributed through cracked software, keygens, torrents, software-sharing sites, and malicious eBook lures, making consumer users a frequent target, although enterprise infections have also been observed. The malware is commonly delivered through multi-stage chains that use disguised installers or loaders, hidden PowerShell, and persistence mechanisms designed to blend into normal system activity.
ViperSoftX is notable for combining infostealing, clipboard hijacking, reconnaissance, persistence, and remote command execution. Its operators have used techniques including WMI Query Language, DLL sideloading or load-order hijacking, PowerShell reflective loading, browser hijacking, and domain generation to protect command-and-control infrastructure. The malware fingerprints infected hosts by collecting system and user information, public IP data, operating system details, application inventory, and security-product presence. It targets cryptocurrency wallets, browser wallet extensions, and password-manager artifacts, including KeePass configurations, and is associated with theft of passwords and cryptocurrency-related data. A core monetization feature is clipboard swapping, in which copied wallet addresses are replaced to redirect cryptocurrency transfers.
Recent PowerShell-based variants show increased modularity, stealth, and resilience. These variants use layered persistence through scheduled tasks, autorun entries, and startup-folder execution, maintain per-infection identifiers, and communicate with command-and-control servers using more evasive request construction and encrypted payload exchange. They can download and execute additional payloads, run attacker-supplied commands, and reset communications state when backend infrastructure changes. ViperSoftX has also used command-and-control concealment methods such as domain-generation algorithms and DNS TXT record abuse.
The malware family is also linked to secondary payload delivery. One prominent associated component is VenomSoftX, a malicious Chromium-based browser extension used for man-in-the-browser style cryptocurrency theft against major exchanges and wallet services. Campaigns associated with ViperSoftX have additionally deployed remote-access and follow-on tooling such as QuasarRAT, PureRAT or PureHVNC, cryptocurrency clippers, and in some reporting, Monero mining payloads. Reporting has suggested multiple operator clusters may be involved based on differences in command-and-control behavior and infrastructure patterns.
ViperSoftX primarily targets Windows systems worldwide, with a strong emphasis on cryptocurrency users and individuals seeking pirated software, but its modular post-compromise capabilities also make it relevant to business environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
the chosen techniques of the actors behind ViperSoftX (which involve using WMI Query Language (WQL), DLL sideloading/DLL load order hijacking, PowerShell reflective loading, browser hijacking, and C&C protection) are sophisticated.
Registers a Windows scheduled task named as WindowsUpdateTask that runs the batch file at user logon, ensuring persistence.
The malware creates a scheduled task using the legacy SyncAppvPublishingServer.vbs script for executing these hidden scripts afterward as well for ensuring persistence.
On top of the information-stealing core, ViperSoftX provides RAT functionalities as well, like executing arbitrary commands on the command line
The current variant, creates PowerShell jobs to run each decoded payload.
The 2024 version ran decoded strings as shell commands using cmd.exe.
In the beginning, ViperSoftX is served to victims when they download what they believe to be cracked software. It is commonly named Activator.exe or Patch.exe. Upon execution, however, the victim is infected with ViperSoftX.
Registers a Windows scheduled task named as WindowsUpdateTask that runs the batch file at user logon, ensuring persistence.
The malware creates a scheduled task using the legacy SyncAppvPublishingServer.vbs script for executing these hidden scripts afterward as well for ensuring persistence.
Registers a Windows scheduled task named as WindowsUpdateTask that runs the batch file at user logon, ensuring persistence.
The malware creates a scheduled task using the legacy SyncAppvPublishingServer.vbs script for executing these hidden scripts afterward as well for ensuring persistence.
it encrypts the payload using a basic XOR cipher ($XOR_KEY=65) and POSTs the encrypted buffer to the C2 server
il exploite l’environnement « AutoIt » pour charger du code dans le Common Language Runtime (CLR)
The 2025 version uses a GUID-style mutex identifier and increases the sleep time to 300 seconds — this delays sandbox detection, increases the likelihood of avoiding behavioral analysis | increases the sleep time to 300 seconds — this delays sandbox detection, increases the likelihood of avoiding behavioral analysis
Les variantes 2025 ajoutent des délais d’exécution destinés à contourner les solutions de sandboxing.
ViperSoftX searches the typical locations for web browser extensions and locally stored wallets.
2025 supports a larger list of extensions and wallets (Exodus, Atomic, Electrum, Ledger), browser extensions (MetaMask, Binance, Coinbase), and Keepass configurations
The 2025 version uses a GUID-style mutex identifier and increases the sleep time to 300 seconds — this delays sandbox detection, increases the likelihood of avoiding behavioral analysis | increases the sleep time to 300 seconds — this delays sandbox detection, increases the likelihood of avoiding behavioral analysis
Les variantes 2025 ajoutent des délais d’exécution destinés à contourner les solutions de sandboxing.
Aside from trying to steal cryptocurrencies, the malware spoofs host headers to obfuscate its communication with the C&C servers.
considering the monthly change of C&C servers and communication exchange, we believe in the possibility of another group involved based on the different coding or C&C scheme.
constructs a HTTP GET request , encodes it in base64... In 2025 it adopts HttpClient ... better compatibility with HTTPS traffic
fetch new commands from C2 ... Receives the C2 server’s response — likely another base64-encoded or encrypted command. Decrypts the received data
53 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-control malware/RAT used to take control of infected Windows systems and steal cryptocurrency wallet addresses via monitoring wallet apps and clipboard hijacking; uses scheduled tasks to run PowerShell, DGA/DNS TXT for C2 discovery, and can download/install additional payloads (including coin miners).
Stealer distributed via cracked software/keygens; uses PowerShell scripts to download additional payloads and execute attacker commands.
Trojan distributed via pirated software/cracks and e-book lures.
A PowerShell-based stealer that uses persistence mechanisms, collects victim and application data, targets cryptocurrency wallets, browser wallet extensions, and KeePass configurations, and communicates with C2 infrastructure using encoded/encrypted requests.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.