Autoit

Malware updated 23 days ago (2024-11-29T14:51:35.115Z)
Download STIX
Preview STIX
AutoIt is a type of malware, a malicious software designed to exploit and damage computers or devices. It infects systems through suspicious downloads, emails, or websites, often without the user's knowledge. Once inside, AutoIt can steal personal information, disrupt operations, or even hold data hostage for ransom. This malware is used in campaigns that employ AutoIt or AutoHotkey scripts to infect victims with DarkGate. The AutoIt script then launches command files and downloads a Python infostealer, causing further harm to the infected system. The attack chain of AutoIt involves an SFX archive that unpacks an AutoIt script and executes a file named "MicrosoftStores.exe". This file then launches the tool MeshAgent, advancing the infection within the system. Additionally, AutoIt uses a variety of programming languages including C++, .NET, Python, VBS, and AutoIt itself. Tools such as tcpview, wireshark, fiddler, procexp, df5serv, OllyDbg, x64dbg, x32dbg, WinDbg, among others, are involved in the process. In the next stage of the infection chain, two DLL files are introduced which use the same technique as the first stage: a legitimate AutoIt interpreter and another A3X implant located in the signature of the legitimate dynamic library. Interestingly, the AutoIt interpreter reads files specified in its launch argument in a unique manner. This sophisticated and multilayered approach makes AutoIt a particularly damaging and persistent form of malware.
Description last updated: 2024-11-28T11:46:02.241Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malware
Windows
Loader
Payload
Python
Credentials
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The Darkgate Malware is associated with Autoit. DarkGate is a multifunctional malware that poses significant threats to computer systems and networks. It has been associated with various malicious activities such as information theft, credential stealing, cryptocurrency theft, and ransomware delivery. DarkGate infiltrates systems through suspicioUnspecified
3
Source Document References
Information about the Autoit Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
DARKReading
a day ago
Unit42
5 months ago
Fortinet
6 months ago
MITRE
2 years ago
Securityaffairs
2 months ago
Securelist
2 months ago
Securelist
3 months ago
Securityaffairs
3 months ago
Fortinet
4 months ago
CrowdStrike
5 months ago
CERT-EU
10 months ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
MITRE
2 years ago
CERT Polska
2 years ago
CERT Polska
2 years ago
CERT Polska
2 years ago