AutoIt
AutoIt is a legitimate Windows automation/scripting interpreter that is frequently abused by threat actors as a malware execution wrapper or backdoor component. The provided reporting describes multiple campaigns in which attackers delivered a legitimate AutoIt binary together with a malicious embedded or external AutoIt script. Observed infection vectors include spear-phishing LNK files that execute malicious PowerShell, use a renamed copy of curl.exe to download payloads, and then register the downloaded AutoIt components in Windows Task Scheduler for persistence; and malware campaigns distributing UPX-packed or compiled AutoIt executables with embedded AutoIt3 scripts. Documented malicious capabilities of the AutoIt-based payloads include command execution, directory listing/search, file upload, and file download. In the Dropping Elephant (also known as Chinastrats/Patchwork) espionage campaign, an UPX-packed AutoIt backdoor was dropped after exploitation of Office vulnerabilities, then used to download additional components, upload basic system information, steal Google Chrome credentials, and beacon to C2 at regular intervals. AutoIt was also observed as an execution layer in a GitHub/Reddit/Discord-driven fake game-cheat campaign that ultimately assembled and executed Vidar 2.0. Reported targeting includes South Korea in APT spear-phishing activity and high-profile diplomatic and economic targets tied to China’s foreign relations. High-confidence indicators directly tied to the AutoIt abuse described include lure filenames such as NTS_환급계좌 등록 및 확인 안내.html.lnk, 2025년 중국 정세 회고와 전망.docx.lnk, 01_다큐멘터리 (임마누엘)제작기획서.pdf.lnk, Finished.pdf.lnk, 그 마을에 가고 싶다_시놉시스.hwp.lnk, 유튜브 캠페인 유료 파트너십 제안.docx.lnk, and 해외 순방 공연 협력 제안서.pdf.lnk.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“Once the payload is executed, an UPX packed AutoIT executable is dropped... the file is an automatically generated AutoIT executable with an AutoIT3 script embedded inside.”
“Once the payload is executed, an UPX packed AutoIT executable is dropped... the file is an automatically generated AutoIT executable with an AutoIT3 script embedded inside.”
“Once the payload is executed, an UPX packed AutoIT executable is dropped... the file is an automatically generated AutoIT executable with an AutoIT3 script embedded inside.”
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Once the payload is executed, an UPX packed AutoIT executable is dropped... the file is an automatically generated AutoIT executable with an AutoIT3 script embedded inside.”
Techniques & procedures
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
3 techniquesAppendix D lists "T1059 Command and Scripting Interpreter" with a note: "In the context of Latin American banking trojans, this means the AutoIt scripting interpreter." The report describes "Method 2: Using the AutoIt interpreter."
Persistence
1 techniquePrivilege Escalation
1 techniqueStealth
3 techniquesThe NetSupportManager RAT was obfuscated by the attacker as ‘21m_18_033.exe’... another executable was dropped via the remote session on the victim’s machine – consoleappmrss.exe.
An obfuscated AutoIt script disguised as Health.exe decrypts and decompresses the Lumma Stealer payload.
.scr (AutoIt compiled binary) used as a loader to execute malicious logic
Command and Control
1 technique외부 URL에 접속하여 추가 파일을 다운로드한다. 최종적으로 정상 AutoIt 프로그램과 악성 AutoIt 스크립트가 다운로드 된다.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious AutoIt script-based backdoor downloaded via LNK spear-phishing. It establishes persistence through Task Scheduler and supports command execution, directory listing, file upload, and file download.
AutoIt-based malicious script/tooling delivered via LNK spearphishing; establishes persistence via Task Scheduler and provides remote command execution plus file discovery and transfer capabilities.
LNK 기반 스피어피싱 체인에서 정상 AutoIt 실행 파일과 함께 악성 AutoIt 스크립트를 내려받아 작업 스케줄러로 지속성을 확보하고, 원격 명령 실행 및 파일/디렉터리 조작(업로드/다운로드 포함) 기능을 수행하는 형태로 사용됨.
AutoIt-compiled payload used as a backdoor/dropper: beacons to C2, uploads basic host info, steals Google Chrome credentials, and downloads additional components (including PowerShell-delivered payloads and a file-stealer module).
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.