Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
AutoHotkeyU32.ahk→an AHK script which sends a POST request to the C&C server and can receive additional AHK script URLs to download and execute.
Once the macros are enabled, two files are extracted from hex encoded cells within the XLSM document.
The victim was instructed to launch Quick Assist and grant the threat actors access. Once connected, threat actors navigated to an Amazon S3-hosted phishing site and downloaded AutoHotkey along with a malicious AutoHotkey script, which was then executed to install Edgecution.
the attack chain... ultimately deploying AutoHotkey-based loaders that reflectively inject a .NET remote access trojan and AsynRAT into memory... That Execute() implements a full process hollowing workflow.
That Execute() implements a full process hollowing workflow... creates a legitimate .NET process in a suspended state... optionally unmaps the original image, allocates memory within the remote process, writes the payload’s headers and sections... and finally resumes the suspended thread.
All strings in the stager are obfuscated by a single-byte XOR routine... The file in question was obfuscated through the free JavaScript obfuscation service Obfuscator.io.
It builds a working folder under a path crafted to mimic a Windows audio diagnostics component, then extracts and decodes embedded blocks into files named to look like Realtek tooling.
the attack chain... ultimately deploying AutoHotkey-based loaders that reflectively inject a .NET remote access trojan and AsynRAT into memory... That Execute() implements a full process hollowing workflow.
That Execute() implements a full process hollowing workflow... creates a legitimate .NET process in a suspended state... optionally unmaps the original image, allocates memory within the remote process, writes the payload’s headers and sections... and finally resumes the suspended thread.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate scripting engine abused here as a loader/execution engine. The attackers renamed AutoHotkey executables to resemble Realtek components and used malicious .ahk scripts to reconstruct payloads and perform process hollowing into legitimate .NET processes.
A legitimate scripting engine abused here as a malware loader/execution framework. The attackers renamed AutoHotkey binaries to resemble Realtek components and used malicious .ahk scripts to reconstruct payloads and perform process hollowing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.