Back to Feed
MalwareMar 6, 2026

Multi-Stage VOID#GEIST Malware Delivering XWorm, AsyncRAT, and Xeno RAT

Securonix Threat Research has disclosed a multi-stage malware campaign called VOID#GEIST that uses obfuscated batch scripts to deliver multiple encrypted remote access trojans including XWorm, AsyncRAT, and Xeno RAT. The attack chain employs a stealthy approach utilizing batch scripts as the initial payload delivery mechanism for various RAT variants.

Summary

Securonix Threat Research has disclosed a multi-stage malware campaign called VOID#GEIST that uses obfuscated batch scripts to deliver multiple encrypted remote access trojans including XWorm, AsyncRAT, and Xeno RAT. The attack chain employs a stealthy approach utilizing batch scripts as the initial payload delivery mechanism for various RAT variants.

Indicators of Compromise

  • malware — VOID#GEIST
  • malware — XWorm
  • malware — AsyncRAT
  • malware — Xeno RAT