logo

CyberGate, RedLine Part of AutoIt Malware Campaign

ID: 56f2d6bf-654e-5a5c-8c47-a921c1114686

STIX ID: report--56f2d6bf-654e-5a5c-8c47-a921c1114686

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes an AutoIt-based malware campaign that distributes CyberGate RAT and RedLine stealer via phishing sites and self-extracting archives; it documents the wrapper behavior, persistence (startup shortcut + VBS), memory-only decryption/injection using RC4, sandbox-evasion checks, custom C2 protocols (RC4+zlib for CyberGate and SOAP-over-HTTP for RedLine), attacker capabilities (credential and cookie theft, keylogging, screen capture, remote execution), command mappings, and a comprehensive set of IOCs and detection guidance including Python decryption scripts and Zscaler detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.