CyberGate, RedLine Part of AutoIt Malware Campaign
ID: 56f2d6bf-654e-5a5c-8c47-a921c1114686
STIX ID: report--56f2d6bf-654e-5a5c-8c47-a921c1114686
Feed Name: Zscaler Security Research Blog
This report analyzes an AutoIt-based malware campaign that distributes CyberGate RAT and RedLine stealer via phishing sites and self-extracting archives; it documents the wrapper behavior, persistence (startup shortcut + VBS), memory-only decryption/injection using RC4, sandbox-evasion checks, custom C2 protocols (RC4+zlib for CyberGate and SOAP-over-HTTP for RedLine), attacker capabilities (credential and cookie theft, keylogging, screen capture, remote execution), command mappings, and a comprehensive set of IOCs and detection guidance including Python decryption scripts and Zscaler detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
