
VOID#GEIST is a stealthy, multi-stage malware delivery framework identified by Securonix Threat Research in early 2026. It is designed to deploy multiple Remote Access Trojans (RATs)—specifically XWorm, AsyncRAT, and Xeno RAT—using a modular, fileless approach to evade detection.
Infection Chain and Mechanisms
The attack is characterized by its reliance on legitimate tools and complex script-based delivery rather than standalone executables.
non.bat) that initiates the infection.python.org to victim systems.spol.bat) into the Windows Startup folder.new.bin, pul.bin, xn.bin) using XOR keys stored in external JSON files.AppInstallerPythonRedirector.exe, is sometimes used to invoke Python and launch payloads like Xeno RAT.explorer.exe. This “fileless” method ensures the malware is never written to disk as an executable, significantly reducing the footprint for traditional antivirus software.According to researchers, the repeated pattern of process injection into explorer.exe over short periods serves as a strong behavioral indicator for detecting this specific campaign.
#deployment #hits #malware #multi-stage #news #rat #systems #void#geist #with — News
© Bulletproof Servers. All rights reserved.