#AutoUpdate
Malware/Tool
2020-06-19 • Kimsuky "AutoUpdate" Malware
AutoUpdate is a suspected Kimsuky-associated downloader identified during activity related to Operation Blue Estimate. ThreatConnect connected samples through a shared string-deobfuscation routine and distinctive URL parameters also present in an ESTsecurity-identified downloader. One sample used a security-themed screen-saver filename and stored an obfuscated command-and-control value resembling that lure. AutoUpdate functions as a downloader within the Kimsuky-linked operation, decoding configuration data, contacting operator infrastructure, and retrieving additional code for execution on compromised Windows systems.
-
2
Tagged Reports
-
1
Unique Authors
-
7
Active Days