#AutoUpdate

Malware/Tool

2020-06-19 • Kimsuky "AutoUpdate" Malware

AutoUpdate is a suspected Kimsuky-associated downloader identified during activity related to Operation Blue Estimate. ThreatConnect connected samples through a shared string-deobfuscation routine and distinctive URL parameters also present in an ESTsecurity-identified downloader. One sample used a security-themed screen-saver filename and stored an obfuscated command-and-control value resembling that lure. AutoUpdate functions as a downloader within the Kimsuky-linked operation, decoding configuration data, contacting operator infrastructure, and retrieving additional code for execution on compromised Windows systems.

Tagged Reports

« Back