autoit3_dropper refers to a class of malware droppers leveraging AutoIT3-compiled scripts to deliver and execute additional payloads on Windows systems. These droppers abuse the FileInstall() function in AutoIT3 to embed and extract malicious payloads, such as obfuscated shellcode, at runtime. The shellcode is typically unpacked, loaded into executable memory using VirtualAlloc, and executed via CallWindowProc() from user32.dll. Obfuscation is achieved through simple character shifting to hide strings and payloads. Recent campaigns have used this technique to deliver Quasar RAT and Phantom stealer, with samples distributed in ZIP archives containing PE files. The use of AutoIT3 allows attackers to bypass some static detection mechanisms by embedding payloads within compiled scripts. Monitoring for FileInstall() usage in AutoIT3 scripts is recommended as an indicator of compromise. This technique, while not new, remains effective and is part of an ongoing wave of similar AutoIT3-based malware campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.