# VOID#GEIST Multi-RAT Campaign — Early Bird APC Injection Delivering XWorm, AsyncRAT, and Xeno RAT via Python Runtime

> Multi-stage fileless malware campaign tracked as VOID#GEIST by Securonix deploys XWorm, AsyncRAT, and Xeno RAT through obfuscated batch scripts that stage a legitimate embedded Python runtime to decrypt and inject shellcode into explorer.exe via Early Bird APC injection, using TryCloudflare tunnels for payload delivery and C2 communication.

- **Published:** 2026-03-08T12:00:00Z
- **Last reviewed:** 2026-03-08T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0196
- **ID:** TL-2026-0196
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 33 (full data via the Threadlinqs MCP server — Purple tier)

## Description

VOID#GEIST is a sophisticated multi-stage malware campaign discovered by Securonix Threat Research (researchers Akshay Gaikwad, Shikha Sangwan, and Aaron Beardslee) and disclosed on March 6, 2026. The campaign demonstrates a significant evolution in script-based malware delivery, shifting away from standalone executables toward complex, modular frameworks that closely mimic legitimate user activity.

The attack chain begins with phishing emails containing links to obfuscated batch scripts hosted on TryCloudflare tunnel domains. Upon execution, the initial batch script performs several actions in parallel: it displays a decoy PDF document in full-screen Google Chrome to distract the user, launches a hidden PowerShell process using the -WindowStyle Hidden parameter to suppress console visibility, and deploys a second batch script to the Windows user Startup directory for persistence.

The malware then contacts TryCloudflare infrastructure to retrieve ZIP archives containing the core payload components: runn.py (a Python-based loader for decryption and injection), encrypted shellcode blobs (new.bin for XWorm, xn.bin for Xeno RAT, pul.bin for AsyncRAT), and JSON key files (a.json, n.json, p.json) containing the decryption keys for each respective payload.

A critical component of the staging phase involves downloading a legitimate Python runtime from python.org, creating a fully self-contained execution environment that eliminates dependencies on the target system. This approach provides portability and reliability for payload execution while appearing benign to security tools that whitelist Python processes.

The runn.py script orchestrates the final payload execution using Early Bird Asynchronous Procedure Call (APC) injection — a variant of process injection mapped to MITRE ATT&CK T1055.004. This technique creates suspended explorer.exe processes, writes decrypted shellcode into their address space, queues the shellcode via QueueUserAPC, and resumes the thread. Because injection occurs before the process entry point and before anti-malware hooks are established, this technique has a higher likelihood of evading AV/EDR detection.

XWorm is deployed first via Early Bird APC injection into explorer.exe. Xeno RAT follows, launched through the legitimate Microsoft binary AppInstallerPythonRedirector.exe to invoke Python — a living-off-the-land technique that abuses trusted system binaries. AsyncRAT is injected last using the same Early Bird APC mechanism.

The infection chain culminates with a minimal HTTP beacon transmitted to attacker-controlled C2 infrastructure hosted on TryCloudflare to confirm successful compromise. The use of TryCloudflare for both payload hosting and C2 provides significant advantages: traffic appears as legitimate HTTPS communication to Cloudflare CDN, benefits from trusted TLS certificates, and many organizations do not explicitly block or monitor trycloudflare.com traffic.

The three RAT payloads provide comprehensive remote access capabilities: XWorm offers keylogging, screenshot capture, webcam access, credential theft, and plugin-based extensibility (35+ plugins in recent versions); AsyncRAT provides real-time monitoring, screen capture, keylogging, file management, and encrypted C2 channels; Xeno RAT delivers HVNC (Hidden Virtual Network Computing), live microphone recording, reverse proxy, and SOCKS5 capabilities.

The campaign operates entirely within user privilege context — no privilege escalation, system-wide registry modifications, scheduled tasks, or service installations are required, making it harder to detect through traditional privilege-based monitoring. Repeated process injection into explorer.exe within short time windows is the strongest behavioral indicator for detection.

---

**Revalidated on 2026-03-12**

No changes to the description are warranted. The existing description accurately covers: (1) the full attack chain from phishing through batch script to Python loader to APC injection, (2) all three RAT payloads (XWorm, AsyncRAT, Xeno RAT), (3) the TryCloudflare delivery mechanism, (4) the AppInstallerPythonRedirector.exe LOLBin abuse, (5) the DuckDNS C2 infrastructure, (6) the decoy PDF distraction technique, (7) persistence via Startup folder, and (8) the modular encrypted shellcode architecture. All of these details have been independently confirmed by multiple secondary sources (Rescana, The Hacker News, SC Media, etc.). One minor note: the Securonix blog title appears to be 'VOID#GEIST: Stealthy Multi-Stage Python Loader' rather than 'VOID#GEIST Campaign Analysis' — the reference URL should be verified.

## MITRE ATT&CK

- T1566.002 Spearphishing Link
- T1059.003 Windows Command Shell
- T1059.006 Python
- T1059.001 PowerShell
- T1204.002 Malicious File
- T1106 Native API
- T1547.001 Registry Run Keys / Startup Folder
- T1055.004 Asynchronous Procedure Call
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1036.005 Match Legitimate Resource Name or Location
- T1564.003 Hidden Window
- T1622 Debugger Evasion
- T1497.001 System Checks
- T1056.001 Keylogging
- T1555 Credentials from Password Stores
- T1057 Process Discovery
- T1033 System Owner/User Discovery
- T1113 Screen Capture
- T1125 Video Capture
- T1071.001 Web Protocols
- T1105 Ingress Tool Transfer
- T1102 Web Service
- T1568 Dynamic Resolution

## Sources

- [Securonix Threat Research: VOID#GEIST Campaign Analysis](https://www.securonix.com/blog/void-geist-multi-rat-campaign/)
- [The Hacker News: Multi-Stage VOID#GEIST Malware Delivering XWorm, AsyncRAT, and Xeno RAT](https://thehackernews.com/2026/03/multi-stage-voidgeist-malware.html)
- [MITRE ATT&CK: Process Injection — Asynchronous Procedure Call (T1055.004)](https://attack.mitre.org/techniques/T1055/004/)
- [MITRE ATT&CK: AsyncRAT Software Entry (S1087)](https://attack.mitre.org/software/S1087/)
- [Forcepoint X-Labs: AsyncRAT Using Python and TryCloudflare for Malware Delivery](https://www.forcepoint.com/blog/x-labs/asyncrat-python-trycloudflare-malware)
- [Cofense: PythonRatLoader — The Proprietor of XWorm and Friends](https://cofense.com/blog/pythonratloader-the-proprietor-of-xworm-and-friends)
- [eSentire: Quartet of Trouble — XWorm, AsyncRAT, VenomRAT, and PureLogs Stealer Leverage TryCloudflare](https://www.esentire.com/blog/quartet-of-trouble-xworm-asyncrat-venomrat-and-purelogs-stealer-leverage-trycloudflare)
- [Rhyno Cybersecurity: VOID#GEIST — The Stealthy Script Attack Taking Over Windows PCs](https://rhyno.io/blogs/cybersecurity-news/voidgeist-the-stealthy-script-attack-taking-over-windows-pcs/)
- [Xeno RAT GitHub Repository](https://github.com/moom825/xeno-rat)
- [Red Team Notes: Early Bird APC Queue Code Injection](https://www.ired.team/offensive-security/code-injection-process-injection/early-bird-apc-queue-code-injection)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0196
