Multi-Stage VOID#GEIST Malware Delivering XWorm, AsyncRAT, and Xeno RAT

The VOID#GEIST malware campaign employs a multi-stage attack using batch scripts to deliver XWorm, AsyncRAT, and Xeno RAT payloads. This stealthy, fileless approach utilizes encrypted shellcode executed in memory via Early Bird APC injection into explorer.exe, making detection difficult by mimicking legitimate administrative activity.

Edward Kiledjian @ekiledjian