{"id":4116,"date":"2022-03-03T19:55:18","date_gmt":"2022-03-04T00:55:18","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=4116"},"modified":"2022-03-03T19:55:19","modified_gmt":"2022-03-04T00:55:19","slug":"beware-of-the-threat-of-soulsearcher","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/beware-of-the-threat-of-soulsearcher\/","title":{"rendered":"Beware of the threat of SoulSearcher"},"content":{"rendered":"\n<p>A threat report published by Symantec in October 2021 caught the attention of cybersecurity experts because it tells of an unknown threat actor running an espionage campaign in Southeast Asia using a new arsenal of custom malware. And it is the mention of a DLL payload loaded from the registry that had not yet been discovered and therefore many paid attention to this threat.<\/p>\n\n\n\n<p>The reason why the module was difficult to find became clear after analyzing its loader. The module is stored as a compressed blob with a custom header in the registry. It never writes itself to disk, so it&#8217;s unlikely it would show up in datasets like VirusTotal.<\/p>\n\n\n\n<p>SoulSearcher malware is highly advanced and one of its main advantages over traditional implants is its ability to operate in fileless mode. You can store your information in the Windows Registry and then operate from Random Access Memory (RAM). It should be noted that this has a modular structure that follows the same modus operandi. This improves SoulSearcher Malware&#8217;s ability to evade some security tools, but you should still be safe from its attack as long as you are using an up-to-date anti-malware service and it is because of this and all threats that exist on the net that it is of the utmost importance to have a good anti-malware.<\/p>\n\n\n\n<p>SoulSearcher Malware code shares some similarities with Gh0st RAT, but it is unclear if the same group of criminals could be behind these two threats. The so-called &#8216;Soul&#8217; modules used by SoulSearcher Malware have virtually endless possibilities, as long as their creators manage to program them to avoid detection. Needless to say, this makes SoulSearcher Malware an extremely dangerous threat that should not be underestimated.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today we will talk about a threat called SoulSearcher which should not be underestimated due to the capacity it can have&#8230;&#8230;<\/p>\n","protected":false},"author":1,"featured_media":4117,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-4116","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Beware of the threat of SoulSearcher - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Today we will talk about a threat called SoulSearcher which should not be underestimated due to the capacity it can have......\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/beware-of-the-threat-of-soulsearcher\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Beware of the threat of SoulSearcher - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Today we will talk about a threat called SoulSearcher which should not be underestimated due to the capacity it can have......\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/beware-of-the-threat-of-soulsearcher\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2022-03-04T00:55:18+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-03-04T00:55:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/03\/Soul.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"795\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/beware-of-the-threat-of-soulsearcher\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/beware-of-the-threat-of-soulsearcher\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Beware of the threat of SoulSearcher\",\"datePublished\":\"2022-03-04T00:55:18+00:00\",\"dateModified\":\"2022-03-04T00:55:19+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/beware-of-the-threat-of-soulsearcher\\\/\"},\"wordCount\":294,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/beware-of-the-threat-of-soulsearcher\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/Soul.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/beware-of-the-threat-of-soulsearcher\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/beware-of-the-threat-of-soulsearcher\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/beware-of-the-threat-of-soulsearcher\\\/\",\"name\":\"Beware of the threat of SoulSearcher - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/beware-of-the-threat-of-soulsearcher\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/beware-of-the-threat-of-soulsearcher\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/Soul.jpg\",\"datePublished\":\"2022-03-04T00:55:18+00:00\",\"dateModified\":\"2022-03-04T00:55:19+00:00\",\"description\":\"Today we will talk about a threat called SoulSearcher which should not be underestimated due to the capacity it can have......\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/beware-of-the-threat-of-soulsearcher\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/beware-of-the-threat-of-soulsearcher\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/beware-of-the-threat-of-soulsearcher\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/Soul.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/Soul.jpg\",\"width\":1200,\"height\":795},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/beware-of-the-threat-of-soulsearcher\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Beware of the threat of SoulSearcher\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Beware of the threat of SoulSearcher - Truxgo Server Blog","description":"Today we will talk about a threat called SoulSearcher which should not be underestimated due to the capacity it can have......","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/beware-of-the-threat-of-soulsearcher\/","og_locale":"es_MX","og_type":"article","og_title":"Beware of the threat of SoulSearcher - Truxgo Server Blog","og_description":"Today we will talk about a threat called SoulSearcher which should not be underestimated due to the capacity it can have......","og_url":"https:\/\/truxgoservers.com\/blog\/beware-of-the-threat-of-soulsearcher\/","og_site_name":"Truxgo Server Blog","article_published_time":"2022-03-04T00:55:18+00:00","article_modified_time":"2022-03-04T00:55:19+00:00","og_image":[{"width":1200,"height":795,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/03\/Soul.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/beware-of-the-threat-of-soulsearcher\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/beware-of-the-threat-of-soulsearcher\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Beware of the threat of SoulSearcher","datePublished":"2022-03-04T00:55:18+00:00","dateModified":"2022-03-04T00:55:19+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/beware-of-the-threat-of-soulsearcher\/"},"wordCount":294,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/beware-of-the-threat-of-soulsearcher\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/03\/Soul.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/beware-of-the-threat-of-soulsearcher\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/beware-of-the-threat-of-soulsearcher\/","url":"https:\/\/truxgoservers.com\/blog\/beware-of-the-threat-of-soulsearcher\/","name":"Beware of the threat of SoulSearcher - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/beware-of-the-threat-of-soulsearcher\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/beware-of-the-threat-of-soulsearcher\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/03\/Soul.jpg","datePublished":"2022-03-04T00:55:18+00:00","dateModified":"2022-03-04T00:55:19+00:00","description":"Today we will talk about a threat called SoulSearcher which should not be underestimated due to the capacity it can have......","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/beware-of-the-threat-of-soulsearcher\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/beware-of-the-threat-of-soulsearcher\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/beware-of-the-threat-of-soulsearcher\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/03\/Soul.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/03\/Soul.jpg","width":1200,"height":795},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/beware-of-the-threat-of-soulsearcher\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Beware of the threat of SoulSearcher"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4116","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=4116"}],"version-history":[{"count":1,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4116\/revisions"}],"predecessor-version":[{"id":4118,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4116\/revisions\/4118"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/4117"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=4116"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=4116"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=4116"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}