#AutoIt

Malware/Tool

2023-12-01 • AutoIt을 사용해 악성코드를 제작하는 Kimsuky 그룹 (RftRAT, Amadey)

AutoIt is a legitimate Windows scripting language and runtime that threat actors use to execute malicious scripts and evade detection; it is not itself malware. In documented KONNI-related activity, attackers delivered a legitimate AutoIt3 executable with an AU3 script, copied both into the public Music folder, and created a scheduled task that ran the script every minute. Other campaigns ported the Lilith remote-access Trojan into AutoIt and used malicious LNK files, PowerShell commands, decoy documents, and downloads from hard-coded attacker servers to launch it.

Tagged Reports

« Back