Skip to main content
Mallory
MalwareUsed by 1 actor

AHK Bot

AHK Bot is an AutoHotkey-based modular post-exploitation malware used in campaigns attributed by Proofpoint to TA866 and also previously associated with Asylum Ambuscade. Proofpoint observed it as a follow-on payload in the TA866 “Screentime” activity cluster, which was active from October 2022 into 2023 and primarily targeted organizations in the United States, with some targeting in Germany, across multiple industries. TA866 campaigns were assessed as largely financially motivated and commonly began with email-delivered malicious attachments or URLs, including macro-enabled Publisher files, JavaScript downloads, PDFs containing URLs, and traffic routed through the 404 TDS. In later activity, Proofpoint also reported TA866 campaigns using invoice-themed emails with PDF attachments containing OneDrive links that led through JavaScript and MSI stages involving WasabiSeed and Screenshotter; prior TA866 campaigns had delivered AHK Bot and Rhadamanthys Stealer.

Within the observed infection chain, a JavaScript downloader installed an MSI containing the WasabiSeed VBS downloader, which established persistence and repeatedly polled command-and-control infrastructure for additional MSI payloads. TA866 used a dedicated Screenshotter payload to capture and exfiltrate desktop screenshots, and Proofpoint assessed the actor likely manually reviewed screenshots before making additional payloads available, including AHK Bot. Proofpoint observed AHK Bot in a December 20, 2022 campaign.

AHK Bot uses AutoHotKey scripts and polls a separate hardcoded C2 from WasabiSeed, using the victim system’s C: drive serial number in the URL path. Observed AHK Bot C2 endpoints included hxxp://89[.]208.105.255/%serial%-du2, hxxp://89[.]208.105.255/%serial%, and hxxp://89[.]208.105.255/download?path=e. Its documented components included a Domain Profiler that determined the infected machine’s Active Directory domain and sent it to C2, and a Stealer Loader that downloaded, decrypted, and executed a DLL in memory. In the observed case, that in-memory payload was Rhadamanthys Stealer, whose sample connected to moosdies[.]top. Proofpoint also noted Russian-language variable names and comments in parts of AHK Bot code, and observed payload availability aligned roughly with 2am to 2pm EST, suggesting an operator time zone of UTC+2 or UTC+3.

Cisco Talos later reported that PS1Bot, a PowerShell/C# malware framework active since early 2025, shares technical overlaps with AHK Bot. Talos described AHK Bot as malware previously used by Asylum Ambuscade and TA866. High-confidence capabilities directly described for AHK Bot in the provided content are AutoHotkey-based modular operation, C2 polling keyed to the victim drive serial number, Active Directory domain profiling, and in-memory loading of Rhadamanthys Stealer.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
TA866

In some cases, Proofpoint observed post-exploitation activity involving AHK Bot and Rhadamanthys Stealer.

via proofpoint threat insight blogproofpoint.com
INDICATORS OF COMPROMISE

IOCs tracked for this family

8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
3 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
4 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app3 years ago
hash.sha256●●●●●●●●●●●●View more in app3 years ago
hash.sha256●●●●●●●●●●●●View more in app3 years ago
ip.v4●●●●●●●●●●●●View more in app3 years ago
uri●●●●●●●●●●●●View more in app3 years ago
uri●●●●●●●●●●●●View more in app3 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching8

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.