VOID#GEIST Malware Hits Systems with Multi-Stage RAT Deployment
Mar 6, 2026 // 19:38 - Lina Schonbein


VOID#GEIST is a stealthy, multi-stage malware delivery framework identified by Securonix Threat Research in early 2026. It is designed to deploy multiple Remote Access Trojans (RATs)—specifically XWorm, AsyncRAT, and Xeno RAT—using a modular, fileless approach to evade detection.

Infection Chain and Mechanisms

The attack is characterized by its reliance on legitimate tools and complex script-based delivery rather than standalone executables.

  • Initial Access: The chain often begins with an obfuscated batch script (e.g., non.bat) that initiates the infection.
  • Staging & Persistence:
    • The malware stages a legitimate Python runtime directly from python.org to victim systems.
    • It establishes persistence by dropping secondary batch scripts (e.g., spol.bat) into the Windows Startup folder.
  • Execution:
    • The framework uses the staged Python environment to run scripts that decrypt shellcode blobs (e.g., new.bin, pul.bin, xn.bin) using XOR keys stored in external JSON files.
    • A legitimate Microsoft binary, AppInstallerPythonRedirector.exe, is sometimes used to invoke Python and launch payloads like Xeno RAT.
  • Stealth Techniques:
    • Early Bird APC Injection: Decrypted payloads are injected directly into separate instances of explorer.exe. This “fileless” method ensures the malware is never written to disk as an executable, significantly reducing the footprint for traditional antivirus software.
    • Infrastructure Abuse: The malware uses TryCloudflare tunneling domains to host its Command and Control (C2) infrastructure, allowing malicious traffic to blend in with legitimate web activity.

According to researchers, the repeated pattern of process injection into explorer.exe over short periods serves as a strong behavioral indicator for detecting this specific campaign.

#deployment  #hits  #malware  #multi-stage  #news  #rat  #systems  #void#geist  #with   —   News