Skip to main content
Mallory
MalwareUsed by 1 actorExploits 3 CVEs

AutoIt

AutoIt is a legitimate Windows automation/scripting interpreter that is frequently abused by threat actors as a malware execution wrapper or backdoor component. The provided reporting describes multiple campaigns in which attackers delivered a legitimate AutoIt binary together with a malicious embedded or external AutoIt script. Observed infection vectors include spear-phishing LNK files that execute malicious PowerShell, use a renamed copy of curl.exe to download payloads, and then register the downloaded AutoIt components in Windows Task Scheduler for persistence; and malware campaigns distributing UPX-packed or compiled AutoIt executables with embedded AutoIt3 scripts. Documented malicious capabilities of the AutoIt-based payloads include command execution, directory listing/search, file upload, and file download. In the Dropping Elephant (also known as Chinastrats/Patchwork) espionage campaign, an UPX-packed AutoIt backdoor was dropped after exploitation of Office vulnerabilities, then used to download additional components, upload basic system information, steal Google Chrome credentials, and beacon to C2 at regular intervals. AutoIt was also observed as an execution layer in a GitHub/Reddit/Discord-driven fake game-cheat campaign that ultimately assembled and executed Vidar 2.0. Reported targeting includes South Korea in APT spear-phishing activity and high-profile diplomatic and economic targets tied to China’s foreign relations. High-confidence indicators directly tied to the AutoIt abuse described include lure filenames such as NTS_환급계좌 등록 및 확인 안내.html.lnk, 2025년 중국 정세 회고와 전망.docx.lnk, 01_다큐멘터리 (임마누엘)제작기획서.pdf.lnk, Finished.pdf.lnk, 그 마을에 가고 싶다_시놉시스.hwp.lnk, 유튜브 캠페인 유료 파트너십 제안.docx.lnk, and 해외 순방 공연 협력 제안서.pdf.lnk.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

3 CVES
CVE-2012-0158MSCOMCTL.OCX ListView/TreeView ActiveX Remote Code Execution

“Once the payload is executed, an UPX packed AutoIT executable is dropped... the file is an automatically generated AutoIT executable with an AutoIT3 script embedded inside.”

via securelistsecurelist.com
CVE-2014-6352Windows OLE remote code execution via crafted OLE object

“Once the payload is executed, an UPX packed AutoIT executable is dropped... the file is an automatically generated AutoIT executable with an AutoIT3 script embedded inside.”

via securelistsecurelist.com
CVE-2014-1761Microsoft Word RTF Memory Corruption RCE

“Once the payload is executed, an UPX packed AutoIT executable is dropped... the file is an automatically generated AutoIT executable with an AutoIT3 script embedded inside.”

via securelistsecurelist.com
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Patchwork

“Once the payload is executed, an UPX packed AutoIT executable is dropped... the file is an automatically generated AutoIT executable with an AutoIT3 script embedded inside.”

via securelistsecurelist.com
MITRE ATT&CK

Techniques & procedures

7 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

3 techniques
T1053.005Scheduled TaskEvidence1

다운로드 된 파일을 작업 스케줄러에 등록하여 지속적으로 실행될 수 있도록 한다.

T1059Command and Scripting InterpreterEvidence4
TacticExecution

Appendix D lists "T1059 Command and Scripting Interpreter" with a note: "In the context of Latin American banking trojans, this means the AutoIt scripting interpreter." The report describes "Method 2: Using the AutoIt interpreter."

T1059.001PowerShellEvidence1
TacticExecution

LNK 파일에 포함된 악성 파워쉘 명령어 실행 시 외부 URL에 접속하여 추가 파일을 다운로드한다.

Persistence

1 technique
T1053.005Scheduled TaskEvidence1

다운로드 된 파일을 작업 스케줄러에 등록하여 지속적으로 실행될 수 있도록 한다.

T1053.005Scheduled TaskEvidence1

다운로드 된 파일을 작업 스케줄러에 등록하여 지속적으로 실행될 수 있도록 한다.

Stealth

3 techniques
T1036MasqueradingEvidence1
TacticStealth

The NetSupportManager RAT was obfuscated by the attacker as ‘21m_18_033.exe’... another executable was dropped via the remote session on the victim’s machine – consoleappmrss.exe.

T1140Deobfuscate/Decode Files or InformationEvidence1
TacticStealth

An obfuscated AutoIt script disguised as Health.exe decrypts and decompresses the Lumma Stealer payload.

T1218System Binary Proxy ExecutionEvidence1
TacticStealth

.scr (AutoIt compiled binary) used as a loader to execute malicious logic

T1105Ingress Tool TransferEvidence1

외부 URL에 접속하여 추가 파일을 다운로드한다. 최종적으로 정상 AutoIt 프로그램과 악성 AutoIt 스크립트가 다운로드 된다.

ACTIVITY FEED

Recent activity

4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities3

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping7

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.