Your Clipboard is Being Watched: How ViperSoftX Steals Crypto
Overview
AhnLab SEcurity intelligence Center (ASEC) has confirmed that the ViperSoftX threat actor is continuing to distribute malware targeting South Korean users. ViperSoftX is malware that resides in infected systems and is responsible for executing commands from the threat actor or exfiltrating cryptocurrency-related information. In May 2024, ASEC analyzed and disclosed a case of attack by the ViperSoftX threat actor. The case involved the distribution of the remote control malware Quasar RAT and TesseractStealer, which exploits Tesseract, an open-source OCR engine based on deep learning.
The ViperSoftX threat actor installs various PowerShell scripts on infected systems and abuses them to download additional payloads. It can carry out various malicious activities upon receiving commands from the threat actor, primarily by installing Quasar RAT for remote control purposes or distributing malware designed to exfiltrate cryptocurrency wallet addresses. Recently, in addition to Quasar RAT, the threat actor has also been observed installing downloader and remote control malware such as PureCrypter and PureHVNC.
Summary
1. Attack Cases
• ViperSoftX has infected numerous systems in South Korea over several years
• These attacks have continued until recently, with the malware remaining on infected systems and persistently installing various additional malicious programs for remote control and information exfiltration
2. Threat Actor Information
• The ViperSoftX attacker was first revealed in 2020, with noticeable activity beginning in late 2019
• They primarily distributed malware disguised as cracked versions or keygens of legitimate software and have recently begun spreading it under the disguise of eBooks via torrents
• The threat actor aims for financial gain by stealing users' cryptocurrency-related information or performing hijacking attacks
• Although it is being distributed worldwide, the malware targets a broad user base and has led to a large number of infections in South Korea
3. Malware Information
• Various techniques are used to evade detection and maintain persistence on infected systems
• Most of the malware used in the attacks is intended to steal cryptocurrency-related information
• Quasar RAT, PureCrypter, and PureHVNC are used to remotely control infected systems
• ClipBanker hijacks the user's copied cryptocurrency wallet address, replacing it with the threat actor's address
• The ViperSoftX PowerShell malware supports both command execution from the threat actor and information exfiltration
• It collects information from infected systems, primarily targeting installed programs related to cryptocurrency or browser extensions associated with cryptocurrency wallets

Figure 1. Flowchart
