AHKBOT is an AutoHotkey-based modular downloader and surveillance malware family used to execute additional AutoHotkey scripts on compromised Windows systems. It has been observed as a lightweight looper or bot component that receives follow-on scripts and plugins from command-and-control infrastructure, enabling operators to extend functionality after initial compromise. Documented modules include screenshot capture, and broader reporting links the family to plugin-based spying capabilities such as keylogging, browser credential theft, process and window enumeration, domain and Active Directory discovery, hVNC deployment, and retrieval and execution of additional payloads including commercial remote access tooling and Cobalt Strike.
AHKBOT has been associated with the threat cluster Asylum Ambuscade, which has used it in both crimeware and espionage operations since at least 2020. In those operations, AHKBOT commonly follows an initial downloader stage such as SunSeed and serves as a second-stage framework for victim surveillance and payload delivery. The group has targeted bank customers, cryptocurrency traders, small and medium businesses, and government entities in Europe and Central Asia, including officials and staff connected to refugee support and state institutions. The malware’s scripting-language implementation and plugin architecture support rapid adaptation and low-friction deployment of new capabilities.
AHKBOT has also been observed in tax-themed phishing campaigns targeting primarily U.S. victims. In one such chain, a malicious macro-enabled Excel lure downloaded an MSI package containing a legitimate AutoHotkey interpreter together with an AHKBOT script. If macros were enabled, the malware was installed and then fetched a screenshotting module for victim monitoring. This delivery pattern shows AHKBOT functioning as a downloader that relies on social engineering and user-enabled document macros for execution.
The malware is best characterized as a modular downloader with post-compromise surveillance functions. Its core behavior centers on fetching and running additional scripts, but its plugin ecosystem enables credential theft, reconnaissance, exfiltration, and broader post-exploitation activity depending on operator objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Earlier this April, the Redmond-based company warned of several phishing campaigns leveraging tax-related themes to deploy malware such as Latrodectus, AHKBot, GuLoader, and BruteRatel C4 (BRc4). The phishing pages, it added, were delivered via RaccoonO365, with one such campaign attributed to an initial access broker called Storm-0249.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Microsoft has observed several phishing campaigns using tax-related themes for social engineering to steal credentials and deploy malware.
The campaign used tax-themed emails that attempted to deliver the red-teaming tool BRc4 and Latrodectus malware... The emails contained a PDF attachment...
If the user opened the Excel file, they were prompted to enable macros, and if the user enabled macros, a malicious MSI file was downloaded and run.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware deployed via phishing campaigns delivered through RaccoonO365.
AutoHotKey-based malware using a simple looping script to fetch/execute additional AHK scripts from C2; observed deploying a screenshot-capture module and exfiltrating screenshots to C2.
An AutoHotKey-based malware framework using a looper script to receive and execute additional scripts, including a screenshot capture module, communicating with a C2 server.
Second-stage AutoHotkey-based modular downloader/spy platform that pulls plugins from C2 to perform screen capture, keylogging, password theft, domain discovery, hVNC deployment, and delivery of additional payloads (including a Cobalt Strike loader and a commercial RAT).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.