Threats

A New Unique RAT Heavily Uses The Autohotkey Scripting Language On An Ongoing Malware Campaign

The Morphisec Labs team has tracked a unique and ongoing RAT delivery campaign that heavily uses the AutoHotKey scripting language, a fork of the AutoIt language that is frequently used for testing purposes.

Researchers identified at least four versions of the RAT delivery campaign, each of which includes multiple advancements and adaptations over the past three months.

Attack Chain Highlighting Rare Techniques that the Attackers Use

  • Manifest flow hijack through VbsEdit manipulation
  • UAC bypass
  • Emulator bypass
  • Tampering with Microsoft Defender and other antivirus products
  • In-place compilation
  • Delivery through text share services

RAT Delivery Campaign

The RAT delivery campaign starts from an AutoHotKey (AHK) compiled script. This is a standalone executable that contains the following: the AHK interpreter, the AHK script, and any files it has incorporated via the FileInstall command.

In this campaign, the attackers incorporate malicious scripts/executables alongside a legitimate application to disguise their intentions.

Researchers observed various RATs distributed via a simple AHK compiled script. They also identified several attack chains all of which start with an AHK executable that leads to the different VBScripts that eventually load the RAT.

Attack Chain

A second version of the malware was found to block connections to popular antivirus solutions by tampering with the victim’s hosts file. “This manipulation denies the DNS resolution for those domains by resolving the localhost IP address instead of the real one,” the researchers explained.

Another loader chain observed that involved delivering the LimeRAT via an obfuscated VBScript, which is then decoded into a PowerShell command that retrieves a C# payload containing the final-stage executable from a Pastebin-like sharing platform service called “stikked.ch.”

Finally, a fourth attack chain discovered used an AHK script to execute a legitimate application, before dropping a VBScript that runs an in-memory PowerShell script to fetch the HCrypt malware loader and install AsyncRAT.

Morphisec researchers attributed all the different attack chains to the same threat actor, citing similarities in the AHK script and overlaps in the techniques used to disable Microsoft Defender.

Final Word

Since threat actors study baseline security controls like emulators, antivirus, and UAC, they develop techniques to bypass and evade them. “The technique changes detailed in this report did not affect the impact of these campaigns. The tactical goals remained the same.

Rather, the technique changes were to bypass passive security controls. A common denominator among these evasive techniques is the abuse of process memory because it’s typically a static and predictable target for the adversary”, Researchers said.

Also Read

Hackers Abuse Microsoft Build Engine to Deliver Password-Stealing Malware Filelessly

TeaBot – A New Malware that stealing victim’s Credentials and Intercepting SMS Messages

Guru Baran

Gurubaran is the Co-Founder and Editor-in-Chief of CyberSecurityNews.com, specializing in vulnerability analysis, malware research, ransomware, and computer forensics.

Recent Posts

China-linked APT24 Hackers New BadAudio Compromised Legitimate Public Websites to Attack Users

APT24, a sophisticated cyber espionage group linked to China's People's Republic, has launched a relentless…

54 minutes ago

Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom's internal systems as part of…

2 hours ago

Critical Grafana Vulnerability Let Attackers Escalate Privilege

Grafana Labs has disclosed a critical security vulnerability affecting Grafana Enterprise that could allow attackers…

2 hours ago

Critical ASUSTOR Vulnerability Let Attackers Execute Malicious Code with Elevated Privileges

A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers…

3 hours ago

Windows 11 to Hide BSOD Crash Errors on Public Displays

Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors…

4 hours ago

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…

6 hours ago