Increase in Distribution of AutoIt Compile Malware via Phishing Emails
ID: b27edd91-b70e-5d31-a2fa-5d8a41403e9c
STIX ID: report--b27edd91-b70e-5d31-a2fa-5d8a41403e9c
Feed Name: ASEC
Threat Score
AhnLab ASEC's weekly phishing distribution report documents a notable increase since August 2024 in malware compiled with AutoIt being distributed via phishing, narrowing the prior dominance of .NET-based malware; the report highlights widespread delivery of infostealers (notably XLoader) and other strains (SnakeKeylogger, RedLine, AgentTesla, RemcosRAT), explains AutoIt EXE structures across versions, and lists sample MD5 indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
