Image for Article: Multi-Stage VOID#GEIST Malware Delivering XWorm, AsyncRAT, and Xeno RAT

Article Details

Title
Article: Multi-Stage VOID#GEIST Malware Delivering XWorm, AsyncRAT, and Xeno RAT
Impact Score
5 / 10
AI Summary (Processed Content)

Researchers have uncovered a multi-stage malware campaign called VOID#GEIST that uses obfuscated batch scripts to deliver encrypted remote access trojans (XWorm, AsyncRAT, Xeno RAT). The attack chain employs a fileless execution method, injecting decrypted shellcode into memory to avoid disk detection and mimic legitimate administrative activity. It begins with a phishing email delivering a batch script, which displays a decoy PDF as a distraction while establishing persistence and fetching encrypted payloads. The malware uses an embedded Python runtime to decrypt and execute the final RAT payloads directly in memory.

Original URL
https://thehackernews.com/2026/03/multi-stage-voidgeist-malware.html
Source Feed
The Hacker News
Published Date
2026-03-06 14:33
Fetched Date
2026-03-06 12:45
Processed Date
2026-03-06 12:46
Embedding Status
Present
Cluster ID
Not Clustered
Raw Extracted Content