Threats Tagged 'autoit'
View all threats tagged with 'autoit'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'autoit'
Click on any threat for detailed analysis and mitigation recommendations
This report details an investigation into a malware operator using GitHub repositories to stage malicious loaders and RAT payloads. The operator's infrastructure includes multiple RAT families such as AsyncRAT, DcRat, Remcos, and XWorm, along with phishing templates targeting Colombian government institutions. The delivery infrastructure spans GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns use judicial notification and traffic violation lures with password-protected archives to target Colombian organizations. The investigation highlights how operational security failures can expose entire malware production workflows beyond individual samples. Join the discussion | AlienVault OTX General | 08/29/2026, 00:24:24 UTC Added: 08/31/2026, 09:52:14 UTC |
In July 2026, multiple APT campaigns targeted South Korean entities using spear phishing emails with malicious LNK files. Seven distinct attack types employed various techniques such as PowerShell scripts, AutoIt programs, DLL side-loading, and curl.exe downloads. Malware was distributed via platforms like GitHub, Google Drive, and Dropbox, disguised as legitimate documents or resumes. The campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate sensitive information and maintain persistence through Task Scheduler entries. Communication with command and control servers used PubNub channels with Base64-encoded data. The attacks focused on deceiving victims with work-related content to execute malicious payloads. Join the discussion | AlienVault OTX General | 08/28/2026, 10:52:45 UTC Added: 08/28/2026, 16:57:13 UTC |
AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats. Join the discussion | AlienVault OTX General | 07/24/2026, 12:34:39 UTC Added: 07/24/2026, 14:52:06 UTC |
Since late March 2026, a large-scale phishing campaign has been deploying malware including Agent Tesla, Remcos, XWorm, and Best Private LOGGER through fileless techniques and low-detection Lua-based loaders. Attackers impersonate well-known companies using business cooperation lures to distribute malicious archives containing obfuscated JavaScript files. These scripts deploy either AutoIt or LuaJIT interpreters alongside disguised scripts masquerading as TrueType Font (.ttf) files. The Lua loaders employ sophisticated anti-analysis techniques including custom ROT ciphers, decoy memory allocation, and Donut shellcode generation for reflective in-memory payload execution. The campaign evolved from simpler implementations in October 2025 to highly complex versions by June 2026, incorporating API unhooking and advanced debugging countermeasures. Victims are ultimately infected with Remote Access Trojans and infostealers that enable full system control and extensive data exfiltration. Join the discussion | AlienVault OTX General | 07/16/2026, 16:06:34 UTC Added: 07/17/2026, 00:32:32 UTC |
Analysts discovered a new Remcos RAT infection chain starting with a batch file executing encoded commands that creates hidden directories and retrieves encrypted payloads. Unlike earlier campaigns relying on PowerShell-hosted .NET loaders, this variant incorporates DonutLoader shellcode and AutoIt-based staging for in-memory payload delivery. The infection begins with a phishing email containing a malicious batch file named Bestellung.CMD. The chain abuses legitimate Windows utilities including cscript.exe and SyncAppvPublishingServer.vbs to execute Base64-encoded payloads. Additional components are downloaded from cloud storage, including 7Zip tools and password-protected archives containing obfuscated JScript. The final payload consists of DonutLoader shellcode that injects Remcos RAT version 7.2.1 Pro into colorcpl.exe, enabling remote control, credential harvesting, keystroke logging, and additional payload deployment. Join the discussion | AlienVault OTX General | 05/30/2026, 00:22:49 UTC Added: 06/01/2026, 09:48:36 UTC |
A sophisticated multi-stage infection chain was identified through proactive threat hunting, beginning with the execution of MicrosoftToolkit.exe, a commonly abused hack tool. The attack employed file masquerading techniques, renaming a .dot file to .bat format to evade detection. The malware performed process discovery and attempted to terminate security-related processes before extracting payloads using extract32.exe. An AutoIt-compiled executable (Replies.scr) functioned as a loader, processing an external encrypted payload file and establishing command-and-control communication with infrastructure associated with Vidar Stealer. The malware demonstrated advanced anti-analysis capabilities, including debugger detection and instrumentation callback queries. It targeted credentials, browser data, cryptocurrency wallets, and system information. Post-execution cleanup routines deleted artifacts and terminated processes to minimize forensic evidence and evade detection, significantly complicating incident res... Join the discussion | AlienVault OTX General | 05/11/2026, 11:49:12 UTC Added: 05/11/2026, 19:06:22 UTC |
This report details the discovery and analysis of a Horabot malware campaign targeting primarily Mexican users. The attack chain begins with a fake CAPTCHA page leading to multiple stages of obfuscated scripts, ultimately delivering an AutoIT loader and a Delphi-based banking Trojan. The malware employs sophisticated encryption techniques, anti-VM checks, and a custom protocol for C2 communication. It also includes a spreader component written in PowerShell that harvests and exfiltrates email addresses to distribute phishing emails. The analysis reveals Brazilian Portuguese comments in the code, suggesting the threat actor's origin. The report provides detection opportunities including YARA rules and hunting queries to identify this threat. Join the discussion | AlienVault OTX General | 03/18/2026, 11:15:06 UTC Added: 03/18/2026, 16:42:29 UTC |
The Konni Group conducted a sophisticated multi-stage attack campaign, initiating with a spear-phishing email disguised as a North Korean human rights lecturer appointment. The attack progressed through execution of a malicious LNK file, installation of remote access malware, and long-term persistence for data theft. A key feature was the unauthorized access to victims' KakaoTalk PC applications, used to distribute additional malicious files to selected contacts. The campaign employed multiple RAT families, including EndRAT, RftRAT, and RemcosRAT, with a distributed C2 infrastructure across Finland, Japan, and the Netherlands. The threat actor's tactics included trust-based propagation, account session abuse, and modular payload deployment, highlighting the need for advanced behavior-based detection and multi-layered defense strategies. Join the discussion | AlienVault OTX General | 03/18/2026, 10:49:03 UTC Added: 03/18/2026, 11:12:34 UTC |
Operation Poseidon is a sophisticated spear-phishing campaign attributed to the Konni APT group. The attackers exploit Google Ads redirection mechanisms to bypass security filters and user awareness. They compromise poorly secured WordPress sites for malware distribution and C2 infrastructure. The campaign uses social engineering tactics, impersonating North Korean human rights organizations and financial institutions. Malware is delivered through LNK files disguised as PDF documents, executing AutoIt scripts that load EndRAT variants. The attackers employ advanced evasion techniques, including email content padding and abuse of legitimate advertising URLs. The campaign demonstrates evolving tactics and infrastructure reuse consistent with previous Konni activities. Join the discussion | AlienVault OTX General | 01/18/2026, 18:38:17 UTC Added: 01/19/2026, 09:26:45 UTC |
The Lumma infostealer is a sophisticated malware distributed as Malware-as-a-Service, targeting Windows systems. It primarily steals sensitive data such as browser credentials, cryptocurrency wallets, and VPN/RDP accounts. Lumma is often used in the initial stages of multi-vector attacks, including ransomware and network breaches. The malware is distributed through phishing sites, disguised as pirated software, and uses complex techniques like NSIS packaging, AutoIt scripts, and process hollowing to evade detection. To combat this threat, organizations should implement behavior-based detection systems and integrate threat intelligence into their security strategies. Join the discussion | AlienVault OTX General | 11/27/2025, 18:43:56 UTC Added: 11/27/2025, 19:03:18 UTC |
Showing 1 to 10 of 17 results