Today > 1 Critical | 3 Medium vulnerabilities   -   You can now download lists of IOCs here!

Increase in Distribution of AutoIt Compile Malware via Phishing Emails

Jan. 10, 2025, 1:12 p.m.

Description

The distribution of malware compiled with AutoIt has been rapidly increasing, surpassing .NET-type malware. AutoIt, a scripting language for Windows automation, is preferred due to its ease of compilation into EXE files and fewer dependencies. The trend began in August 2024, with AutoIt malware nearly matching .NET malware distribution by December. XLoader was the most distributed malware, followed by SnakeKeylogger, RedLine, AgentTesla, and RemcosRAT. The report discusses the structure of AutoIt executables, noting changes in how the script is included and encrypted in different versions. Three specific cases of AutoIt malware distribution are mentioned, highlighting the growing threat posed by this type of malware in phishing campaigns.

Date

Published: Jan. 10, 2025, 12:52 p.m.

Created: Jan. 10, 2025, 12:52 p.m.

Modified: Jan. 10, 2025, 1:12 p.m.

Indicators

f8c3f6b1795091d7211dc5b0d508c9ffa115e6fbbab18b4ee9545b2124e211e5

17a478564c4eb41b217ae131ab1b433278bb60bd0d4b0f876f602d71336abae3

0d76a185c479321a6eb599b67de8126eb81d5e3f8a1b9d93c0abaeeef9c89e40

Attack Patterns

SnakeKeylogger

RemcosRAT

XLoader

RedLine

AgentTesla

T1588.002

T1059.005

T1204

T1140

T1027

T1566