Threat reportMalwareTL-2026-0196

VOID#GEIST Multi-RAT Campaign — Early Bird APC Injection Delivering XWorm, AsyncRAT, and Xeno RAT via Python Runtime

highMONITORING

VOID#GEIST Multi-RAT Campaign (TL-2026-0196), also tracked as VOID#GEIST, is a high-severity malware campaign, first published 2026-03-08. It has no confirmed attribution, affects Microsoft Windows, maps to 24 MITRE ATT&CK techniques (T1027, T1033, T1036.005), and is covered by 9 detection rules and 33 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
24MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
33Indicators of compromise

Key facts for TL-2026-0196

Threat ID
TL-2026-0196
Also known as
VOID#GEIST
Severity
HIGH
Status
MONITORING
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
government, financial, technology, healthcare, manufacturing, energy
Target regions
North America, Europe, Asia Pacific
Detection rules
9
Indicators of compromise
33

Malware and tooling in VOID#GEIST Multi-RAT Campaign

Malware and tooling: AsyncRAT, XWorm, XenoRAT

How VOID#GEIST Multi-RAT Campaign works

Multi-stage fileless malware campaign tracked as VOID#GEIST by Securonix deploys XWorm, AsyncRAT, and Xeno RAT through obfuscated batch scripts that stage a legitimate embedded Python runtime to decrypt and inject shellcode into explorer.exe via Early Bird APC injection, using TryCloudflare tunnels for payload delivery and C2 communication.

VOID#GEIST is a sophisticated multi-stage malware campaign discovered by Securonix Threat Research (researchers Akshay Gaikwad, Shikha Sangwan, and Aaron Beardslee) and disclosed on March 6, 2026. The campaign demonstrates a significant evolution in script-based malware delivery, shifting away from standalone executables toward complex, modular frameworks that closely mimic legitimate user activity.

The attack chain begins with phishing emails containing links to obfuscated batch scripts hosted on TryCloudflare tunnel domains. Upon execution, the initial batch script performs several actions in parallel: it displays a decoy PDF document in full-screen Google Chrome to distract the user, launches a hidden PowerShell process using the -WindowStyle Hidden parameter to suppress console visibility, and deploys a second batch script to the Windows user Startup directory for persistence.

The malware then contacts TryCloudflare infrastructure to retrieve ZIP archives containing the core payload components: runn.py (a Python-based loader for decryption and injection), encrypted shellcode blobs (new.bin for XWorm, xn.bin for Xeno RAT, pul.bin for AsyncRAT), and JSON key files (a.json, n.json, p.json) containing the decryption keys for each respective payload.

A critical component of the staging phase involves downloading a legitimate Python runtime from python.org, creating a fully self-contained execution environment that eliminates dependencies on the target system. This approach provides portability and reliability for payload execution while appearing benign to security tools that whitelist Python processes.

The runn.py script orchestrates the final payload execution using Early Bird Asynchronous Procedure Call (APC) injection — a variant of process injection mapped to MITRE ATT&CK T1055.004. This technique creates suspended explorer.exe processes, writes decrypted shellcode into their address space, queues the shellcode via QueueUserAPC, and resumes the thread. Because injection occurs before the process entry point and before anti-malware hooks are established, this technique has a higher likelihood of evading AV/EDR detection.

XWorm is deployed first via Early Bird APC injection into explorer.exe. Xeno RAT follows, launched through the legitimate Microsoft binary AppInstallerPythonRedirector.exe to invoke Python — a living-off-the-land technique that abuses trusted system binaries. AsyncRAT is injected last using the same Early Bird APC mechanism.

The infection chain culminates with a minimal HTTP beacon transmitted to attacker-controlled C2 infrastructure hosted on TryCloudflare to confirm successful compromise. The use of TryCloudflare for both payload hosting and C2 provides significant advantages: traffic appears as legitimate HTTPS communication to Cloudflare CDN, benefits from trusted TLS certificates, and many organizations do not explicitly block or monitor trycloudflare.com traffic.

The three RAT payloads provide comprehensive remote access capabilities: XWorm offers keylogging, screenshot capture, webcam access, credential theft, and plugin-based extensibility (35+ plugins in recent versions); AsyncRAT provides real-time monitoring, screen capture, keylogging, file management, and encrypted C2 channels; Xeno RAT delivers HVNC (Hidden Virtual Network Computing), live microphone recording, reverse proxy, and SOCKS5 capabilities.

The campaign operates entirely within user privilege context — no privilege escalation, system-wide registry modifications, scheduled tasks, or service installations are required, making it harder to detect through traditional privilege-based monitoring. Repeated process injection into explorer.exe within short time windows is the strongest behavioral indicator for detection.

---

**Revalidated on 2026-03-12**

No changes to the description are warranted. The existing description accurately covers: (1) the full attack chain from phishing through batch script to Python loader to APC injection, (2) all three RAT payloads (XWorm, AsyncRAT, Xeno RAT), (3) the TryCloudflare delivery mechanism, (4) the AppInstallerPythonRedirector.exe LOLBin abuse, (5) the DuckDNS C2 infrastructure, (6) the decoy PDF distraction technique, (7) persistence via Startup folder, and (8) the modular encrypted shellcode architecture. All of these details have been independently confirmed by multiple secondary sources (Rescana, The Hacker News, SC Media, etc.). One minor note: the Securonix blog title appears to be 'VOID#GEIST: Stealthy Multi-Stage Python Loader' rather than 'VOID#GEIST Campaign Analysis' — the reference URL should be verified.

MITRE ATT&CK techniques used in TL-2026-0196

defense-evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1055.004 Asynchronous Procedure Call; T1140 Deobfuscate/Decode Files or Information; T1497.001 System Checks; T1564.003 Hidden Window; T1622 Debugger Evasion

discovery

T1033 System Owner/User Discovery; T1057 Process Discovery

collection

T1056.001 Keylogging; T1113 Screen Capture; T1125 Video Capture

execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.006 Python; T1106 Native API; T1204.002 Malicious File

command-and-control

T1071.001 Web Protocols; T1102 Web Service; T1105 Ingress Tool Transfer; T1568 Dynamic Resolution

persistence

T1547.001 Registry Run Keys / Startup Folder

credential-access

T1555 Credentials from Password Stores

initial-access

T1566.002 Spearphishing Link

Affected products and versions in VOID#GEIST Multi-RAT Campaign

  • Microsoft — Windows
    Vulnerable versions: Windows 10; Windows 11; Windows Server 2016; Windows Server 2019; Windows Server 2022

Remediation for VOID#GEIST Multi-RAT Campaign

Immediate actions

  • Block TryCloudflare tunnel domains at web proxy and DNS level (*.trycloudflare.com)
  • Block known DuckDNS C2 domains at DNS level (*.duckdns.org)
  • Hunt for multiple explorer.exe instances with injected memory regions
  • Search for runn.py, new.bin, xn.bin, pul.bin artifacts in user-writable directories
  • Check Windows Startup folders for unauthorized batch scripts
  • Monitor for AppInstallerPythonRedirector.exe executing Python scripts

Workarounds

  • Restrict execution of batch scripts from user download directories via Group Policy
  • Block Python runtime downloads from non-approved sources
  • Disable or restrict AppInstallerPythonRedirector.exe via application control policy
  • Enable Attack Surface Reduction rules for process injection prevention

Longer-term hardening

  • Deploy EDR with behavioral detection for Early Bird APC injection patterns
  • Implement application whitelisting to prevent unauthorized Python runtime execution
  • Configure SIEM rules to detect rapid sequential process injection into explorer.exe
  • Establish baseline monitoring for TryCloudflare and DuckDNS domain communications
  • Deploy memory integrity monitoring for critical system processes
  • Enable PowerShell script block logging and constrained language mode

Timeline of VOID#GEIST Multi-RAT Campaign

  • Earlier TryCloudflare-based RAT delivery campaigns documented by Forcepoint and eSentire, establishing the Python+TryCloudflare delivery pattern later adopted by VOID#GEIST
  • Cofense documents PythonRatLoader campaigns delivering XWorm and other RATs via TryCloudflare tunnels with Python-based loaders, a direct precursor to VOID#GEIST techniques
  • Estimated start of VOID#GEIST campaign activity based on infrastructure analysis and earliest observed phishing lures
  • Securonix Threat Research collects VOID#GEIST malware samples and begins analysis of the multi-stage batch-to-Python-to-APC injection chain
  • TipRanks publishes threat research spotlight highlighting Securonix''s detection role in the VOID#GEIST campaign
  • Rescana publishes comprehensive technical analysis expanding on Securonix original research, confirming all IOCs and TTPs
  • The Hacker News, BleepingComputer, and multiple security news outlets publish coverage of VOID#GEIST campaign findings
  • Securonix Threat Research publicly discloses VOID#GEIST campaign with full technical analysis by researchers Akshay Gaikwad, Shikha Sangwan, and Aaron Beardslee
  • Campaign remains active with no confirmed attribution. Continued monitoring for new TryCloudflare tunnel infrastructure and updated payloads
  • Revalidation confirms campaign remains active with no new IOCs, attribution, or confirmed victims reported since initial disclosure
  • As of 2026-05-29, VOID#GEIST remains a live, unattributed malware campaign with no CVE to patch, no disruption/attribution, and no successor — its TryCloudflare/Python/Early Bird APC RAT-delivery pattern is still actively used industry-wide. However, no fresh IOCs or confirmed activity for this specific named campaign have surfaced since the March 2026 Securonix disclosure, so it is downgraded ACTIVE to MONITORING.

Sources cited for VOID#GEIST Multi-RAT Campaign

Detection coverage for TL-2026-0196

As of 2026-03-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0196 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
33 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats