As cited
Copy frozen at (site build).
threat intel
AutoIT Payload Injector
A wave of phishing emails delivering fake bank statements in RAR archives initiates a multi-stage malware infection chain using VBS, PowerShell, and AutoIT scripts. The attack culminates in process injection of shellcode into charmap.exe through the AutoIT3 interpreter, establishing persistence via Windows registry Run keys. The attackers employ Base64 encoding, XOR encryption, and obfuscation techniques throughout the delivery pipeline.
Why it matters: Practitioners should monitor for RAR-based phishing campaigns and emails impersonating financial institutions, as this technique chains accessible scripting languages to achieve code execution and persistence on Windows endpoints.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
AutoIT Payload Injector
A wave of phishing emails delivering fake bank statements in RAR archives initiates a multi-stage malware infection chain using VBS, PowerShell, and AutoIT scripts. The attack culminates in process injection of shellcode into charmap.exe through the AutoIT3 interpreter, establishing persistence via Windows registry Run keys. The attackers employ Base64 encoding, XOR encryption, and obfuscation techniques throughout the delivery pipeline.
Why it matters: Practitioners should monitor for RAR-based phishing campaigns and emails impersonating financial institutions, as this technique chains accessible scripting languages to achieve code execution and persistence on Windows endpoints.
- Source published
- First seen by Cybersecurity Tracker