RAT Dropped By Two Layers of AutoIT Code, (Mon, May 19th)
SANS Internet Storm Center, InfoCON: green 2025-05-19
Summary:
Like .Net, AutoIT&#;x26;#;x5b;1&#;x26;#;x5d; remains a popular language for years in the malware ecosystem. It&#;x26;#;39;s a simple language that can interact with all the components of the Windows operating system. I regularly discover AutoIT3 binaries (yes, it can be compiled). This weekend, I found a malware delivered through a double layer of AutoIT code!