AuTo Stealer is a malware family associated with host reconnaissance, file collection, local staging, and command-and-control-based data theft on Windows systems. It gathers basic victim profiling information including the current username, hostname, operating system details, and installed antivirus products, indicating both system discovery and security software discovery functionality. It also collects files of interest from compromised machines, including common office documents, PDFs, text files, database files, and image files.
Before exfiltration, AuTo Stealer can stage harvested information locally in a text file derived from host and user identifiers. It then transmits stolen data to actor-controlled command-and-control infrastructure over HTTP or TCP, using the same remote communications channel for exfiltration. Reported behavior is consistent with an information-stealing malware family focused on collecting host metadata and user files from infected endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions. | APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution. Blue Mockingbird has used batch script files to automate execution and deployment of payloads. During HomeLand Justice, threat actors used Windows batch files for persistence and execution.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content repeatedly describes threat actors and malware collecting, stealing, identifying, copying, or staging files, documents, credentials, logs, databases, and other information from compromised hosts or local systems.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer capable of collecting the username from an infected host.
Stealer malware that can collect information about installed antivirus products.
Stealer malware that collects information about installed antivirus products.
Stealer malware that exfiltrates data over actor-controlled C2 infrastructure via HTTP or TCP.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.