Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The FBI identified several malicious AutoIt malware scripts used by Rana. The FBI assesses the AutoIt malware was embedded in Microsoft Office documents or malicious links, and sent to victims via spear phishing or other social engineering techniques.
The FBI identified several malicious AutoIt malware scripts used by Rana. The FBI assesses the AutoIt malware was embedded in Microsoft Office documents or malicious links, and sent to victims via spear phishing or other social engineering techniques.
The FBI identified several malicious AutoIt malware scripts used by Rana. The FBI assesses the AutoIt malware was embedded in Microsoft Office documents or malicious links, and sent to victims via spear phishing or other social engineering techniques.
The FBI identified several malicious AutoIt malware scripts used by Rana. The FBI assesses the AutoIt malware was embedded in Microsoft Office documents or malicious links, and sent to victims via spear phishing or other social engineering techniques.
The FBI identified several malicious AutoIt malware scripts used by Rana. The FBI assesses the AutoIt malware was embedded in Microsoft Office documents or malicious links, and sent to victims via spear phishing or other social engineering techniques.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
“The downloaded file is registered in the task scheduler so that it can be executed continuously.”
The FBI identified several malicious AutoIt malware scripts used by Rana.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware leveraging AutoIt scripting to provide backdoor access, command execution, file upload/download, and persistence via task scheduler.
A malicious AutoIt script family used by Rana that establishes directories and registry values, selects among multiple C2 methods, invokes PowerShell payloads, and uploads/downloads commands and files via update.php endpoints.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.