Unmasking a Multi-Stage Loader: AutoIt Abuse Leading to Vidar Stealer Command-and-Control Communication
May 11, 2026, 7:27 p.m.
Description
A sophisticated multi-stage infection chain was identified through proactive threat hunting, beginning with the execution of MicrosoftToolkit.exe, a commonly abused hack tool. The attack employed file masquerading techniques, renaming a .dot file to .bat format to evade detection. The malware performed process discovery and attempted to terminate security-related processes before extracting payloads using extract32.exe. An AutoIt-compiled executable (Replies.scr) functioned as a loader, processing an external encrypted payload file and establishing command-and-control communication with infrastructure associated with Vidar Stealer. The malware demonstrated advanced anti-analysis capabilities, including debugger detection and instrumentation callback queries. It targeted credentials, browser data, cryptocurrency wallets, and system information. Post-execution cleanup routines deleted artifacts and terminated processes to minimize forensic evidence and evade detection, significantly complicating incident res...
Tags
Date
- Created: May 11, 2026, 11:49 a.m.
- Published: May 11, 2026, 11:49 a.m.
- Modified: May 11, 2026, 7:27 p.m.
Indicators
- d4fe9f48178cdf375a3be30d17f1dc016b5861dff8683f0bb35a0ba8d44f892f
- fc27479ff929d846e7c5c5d147479c81e483a2ec911bd1501a53aa646a29620d
- 881619a47b62b52305d92640cc4d4845a279c23a5a749413785fc8fcb0fdf7fb
- 968ecf51c442ec0ff91f91689ac524e7e8e9eab0c1a2a65cf13e54cf95194efe
- 978ad86c90d85b74947bb627ec24f8bcd26812b500e82f5af202160506ac29c6
Additional Informations
- gz.technicalprorj.xyz
- 7ctelegram.me