logo

Keitaro TDS abused to deliver AutoIT-based loader targeting German speakers · Blog · Sublime Security

ID: 884d590b-1334-5b5f-951b-11639dec97d2

STIX ID: report--884d590b-1334-5b5f-951b-11639dec97d2

Feed Name: Sublime Security Blog

Threat Score
70/100

Date Published: 2026-01-09

Date Updated: 2026-05-01

...
...

This report documents a targeted malvertising campaign that uses Keitaro TDS redirects to deliver a deliberately oversized ISO which, once mounted, extracts a password-protected executable that builds and runs an AutoIt-based loader. The payload performs AV/service checks, drops numerous artifacts to %LocalAppData%, creates a scheduled task (DragonMapper) for persistence, and exhibits behaviors consistent with information-stealer families; the report includes file hashes, malicious domains, and network indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.