Threat reportMalwareTL-2026-0196
VOID#GEIST Multi-RAT Campaign — Early Bird APC Injection Delivering XWorm, AsyncRAT, and Xeno RAT via Python Runtime
VOID#GEIST Multi-RAT Campaign (TL-2026-0196), also tracked as VOID#GEIST, is a high-severity malware campaign, first published 2026-03-08. It has no confirmed attribution, affects Microsoft Windows, maps to 24 MITRE ATT&CK techniques (T1027, T1033, T1036.005), and is covered by 9 detection rules and 33 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 24MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 33Indicators of compromise
Key facts for TL-2026-0196
- Threat ID
- TL-2026-0196
- Also known as
- VOID#GEIST
- Severity
- HIGH
- Status
- MONITORING
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- government, financial, technology, healthcare, manufacturing, energy
- Target regions
- North America, Europe, Asia Pacific
- Detection rules
- 9
- Indicators of compromise
- 33
Malware and tooling in VOID#GEIST Multi-RAT Campaign
Malware and tooling: AsyncRAT, XWorm, XenoRAT
How VOID#GEIST Multi-RAT Campaign works
Multi-stage fileless malware campaign tracked as VOID#GEIST by Securonix deploys XWorm, AsyncRAT, and Xeno RAT through obfuscated batch scripts that stage a legitimate embedded Python runtime to decrypt and inject shellcode into explorer.exe via Early Bird APC injection, using TryCloudflare tunnels for payload delivery and C2 communication.
VOID#GEIST is a sophisticated multi-stage malware campaign discovered by Securonix Threat Research (researchers Akshay Gaikwad, Shikha Sangwan, and Aaron Beardslee) and disclosed on March 6, 2026. The campaign demonstrates a significant evolution in script-based malware delivery, shifting away from standalone executables toward complex, modular frameworks that closely mimic legitimate user activity.
The attack chain begins with phishing emails containing links to obfuscated batch scripts hosted on TryCloudflare tunnel domains. Upon execution, the initial batch script performs several actions in parallel: it displays a decoy PDF document in full-screen Google Chrome to distract the user, launches a hidden PowerShell process using the -WindowStyle Hidden parameter to suppress console visibility, and deploys a second batch script to the Windows user Startup directory for persistence.
The malware then contacts TryCloudflare infrastructure to retrieve ZIP archives containing the core payload components: runn.py (a Python-based loader for decryption and injection), encrypted shellcode blobs (new.bin for XWorm, xn.bin for Xeno RAT, pul.bin for AsyncRAT), and JSON key files (a.json, n.json, p.json) containing the decryption keys for each respective payload.
A critical component of the staging phase involves downloading a legitimate Python runtime from python.org, creating a fully self-contained execution environment that eliminates dependencies on the target system. This approach provides portability and reliability for payload execution while appearing benign to security tools that whitelist Python processes.
The runn.py script orchestrates the final payload execution using Early Bird Asynchronous Procedure Call (APC) injection — a variant of process injection mapped to MITRE ATT&CK T1055.004. This technique creates suspended explorer.exe processes, writes decrypted shellcode into their address space, queues the shellcode via QueueUserAPC, and resumes the thread. Because injection occurs before the process entry point and before anti-malware hooks are established, this technique has a higher likelihood of evading AV/EDR detection.
XWorm is deployed first via Early Bird APC injection into explorer.exe. Xeno RAT follows, launched through the legitimate Microsoft binary AppInstallerPythonRedirector.exe to invoke Python — a living-off-the-land technique that abuses trusted system binaries. AsyncRAT is injected last using the same Early Bird APC mechanism.
The infection chain culminates with a minimal HTTP beacon transmitted to attacker-controlled C2 infrastructure hosted on TryCloudflare to confirm successful compromise. The use of TryCloudflare for both payload hosting and C2 provides significant advantages: traffic appears as legitimate HTTPS communication to Cloudflare CDN, benefits from trusted TLS certificates, and many organizations do not explicitly block or monitor trycloudflare.com traffic.
The three RAT payloads provide comprehensive remote access capabilities: XWorm offers keylogging, screenshot capture, webcam access, credential theft, and plugin-based extensibility (35+ plugins in recent versions); AsyncRAT provides real-time monitoring, screen capture, keylogging, file management, and encrypted C2 channels; Xeno RAT delivers HVNC (Hidden Virtual Network Computing), live microphone recording, reverse proxy, and SOCKS5 capabilities.
The campaign operates entirely within user privilege context — no privilege escalation, system-wide registry modifications, scheduled tasks, or service installations are required, making it harder to detect through traditional privilege-based monitoring. Repeated process injection into explorer.exe within short time windows is the strongest behavioral indicator for detection.
---
**Revalidated on 2026-03-12**
No changes to the description are warranted. The existing description accurately covers: (1) the full attack chain from phishing through batch script to Python loader to APC injection, (2) all three RAT payloads (XWorm, AsyncRAT, Xeno RAT), (3) the TryCloudflare delivery mechanism, (4) the AppInstallerPythonRedirector.exe LOLBin abuse, (5) the DuckDNS C2 infrastructure, (6) the decoy PDF distraction technique, (7) persistence via Startup folder, and (8) the modular encrypted shellcode architecture. All of these details have been independently confirmed by multiple secondary sources (Rescana, The Hacker News, SC Media, etc.). One minor note: the Securonix blog title appears to be 'VOID#GEIST: Stealthy Multi-Stage Python Loader' rather than 'VOID#GEIST Campaign Analysis' — the reference URL should be verified.
MITRE ATT&CK techniques used in TL-2026-0196
defense-evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1055.004 Asynchronous Procedure Call; T1140 Deobfuscate/Decode Files or Information; T1497.001 System Checks; T1564.003 Hidden Window; T1622 Debugger Evasion
discovery
T1033 System Owner/User Discovery; T1057 Process Discovery
collection
T1056.001 Keylogging; T1113 Screen Capture; T1125 Video Capture
execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.006 Python; T1106 Native API; T1204.002 Malicious File
command-and-control
T1071.001 Web Protocols; T1102 Web Service; T1105 Ingress Tool Transfer; T1568 Dynamic Resolution
persistence
T1547.001 Registry Run Keys / Startup Folder
credential-access
T1555 Credentials from Password Stores
initial-access
Affected products and versions in VOID#GEIST Multi-RAT Campaign
- Microsoft — Windows
Vulnerable versions: Windows 10; Windows 11; Windows Server 2016; Windows Server 2019; Windows Server 2022
Remediation for VOID#GEIST Multi-RAT Campaign
Immediate actions
- Block TryCloudflare tunnel domains at web proxy and DNS level (*.trycloudflare.com)
- Block known DuckDNS C2 domains at DNS level (*.duckdns.org)
- Hunt for multiple explorer.exe instances with injected memory regions
- Search for runn.py, new.bin, xn.bin, pul.bin artifacts in user-writable directories
- Check Windows Startup folders for unauthorized batch scripts
- Monitor for AppInstallerPythonRedirector.exe executing Python scripts
Workarounds
- Restrict execution of batch scripts from user download directories via Group Policy
- Block Python runtime downloads from non-approved sources
- Disable or restrict AppInstallerPythonRedirector.exe via application control policy
- Enable Attack Surface Reduction rules for process injection prevention
Longer-term hardening
- Deploy EDR with behavioral detection for Early Bird APC injection patterns
- Implement application whitelisting to prevent unauthorized Python runtime execution
- Configure SIEM rules to detect rapid sequential process injection into explorer.exe
- Establish baseline monitoring for TryCloudflare and DuckDNS domain communications
- Deploy memory integrity monitoring for critical system processes
- Enable PowerShell script block logging and constrained language mode
Timeline of VOID#GEIST Multi-RAT Campaign
- Earlier TryCloudflare-based RAT delivery campaigns documented by Forcepoint and eSentire, establishing the Python+TryCloudflare delivery pattern later adopted by VOID#GEIST
- Cofense documents PythonRatLoader campaigns delivering XWorm and other RATs via TryCloudflare tunnels with Python-based loaders, a direct precursor to VOID#GEIST techniques
- Estimated start of VOID#GEIST campaign activity based on infrastructure analysis and earliest observed phishing lures
- Securonix Threat Research collects VOID#GEIST malware samples and begins analysis of the multi-stage batch-to-Python-to-APC injection chain
- TipRanks publishes threat research spotlight highlighting Securonix''s detection role in the VOID#GEIST campaign
- Rescana publishes comprehensive technical analysis expanding on Securonix original research, confirming all IOCs and TTPs
- The Hacker News, BleepingComputer, and multiple security news outlets publish coverage of VOID#GEIST campaign findings
- Securonix Threat Research publicly discloses VOID#GEIST campaign with full technical analysis by researchers Akshay Gaikwad, Shikha Sangwan, and Aaron Beardslee
- Campaign remains active with no confirmed attribution. Continued monitoring for new TryCloudflare tunnel infrastructure and updated payloads
- Revalidation confirms campaign remains active with no new IOCs, attribution, or confirmed victims reported since initial disclosure
- As of 2026-05-29, VOID#GEIST remains a live, unattributed malware campaign with no CVE to patch, no disruption/attribution, and no successor — its TryCloudflare/Python/Early Bird APC RAT-delivery pattern is still actively used industry-wide. However, no fresh IOCs or confirmed activity for this specific named campaign have surfaced since the March 2026 Securonix disclosure, so it is downgraded ACTIVE to MONITORING.
Sources cited for VOID#GEIST Multi-RAT Campaign
- Securonix Threat Research: VOID#GEIST Campaign Analysis
- The Hacker News: Multi-Stage VOID#GEIST Malware Delivering XWorm, AsyncRAT, and Xeno RAT
- MITRE ATT&CK: Process Injection — Asynchronous Procedure Call (T1055.004)
- MITRE ATT&CK: AsyncRAT Software Entry (S1087)
- Forcepoint X-Labs: AsyncRAT Using Python and TryCloudflare for Malware Delivery
- Cofense: PythonRatLoader — The Proprietor of XWorm and Friends
- eSentire: Quartet of Trouble — XWorm, AsyncRAT, VenomRAT, and PureLogs Stealer Leverage TryCloudflare
- Rhyno Cybersecurity: VOID#GEIST — The Stealthy Script Attack Taking Over Windows PCs
- Xeno RAT GitHub Repository
- Red Team Notes: Early Bird APC Queue Code Injection
Detection coverage for TL-2026-0196
As of 2026-03-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0196 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.