AutoIt backdoor is a Windows backdoor implemented with AutoIt that supports command-and-control communications, PowerShell-based staging, privilege escalation, and victim file discovery. Reported behavior includes sending Base64-encoded command-and-control responses, downloading PowerShell content that decodes into a shellcode loader, and attempting to elevate privileges by bypassing Windows User Account Control. It also enumerates victim documents and other potentially valuable files by extension, indicating collection-oriented reconnaissance and post-compromise targeting of user data. The malware is associated with in-memory or script-based follow-on execution through PowerShell rather than functioning solely as a standalone payload. Available reporting supports its use as a post-compromise access and execution component on Windows systems, but does not establish a more specific delivery vector or a confidently attributed threat actor from the supplied facts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
Multiple entries state PowerShell was used to 'download and execute payloads,' 'download additional scripts,' 'retrieve the malicious payload,' or 'download files from the C2 server.'
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that downloads a PowerShell-based shellcode loader.
Backdoor that downloads a PowerShell script which decodes into a shellcode loader.
Backdoor that uses Base64-encoded command-and-control responses.
Backdoor that retrieves a PowerShell-based shellcode loader.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.