Malware.View on attack.mitre.org
AutoIt backdoor is malware that has been used by the actors responsible for the MONSOON campaign. The actors frequently used it in weaponized .pps files exploiting CVE-2014-6352. This malware makes use of the legitimate scripting language for Windows GUI automation with the same name.
| Technique | Procedure example |
|---|---|
| T1059.001 PowerShell |
AutoIt backdoor downloads a PowerShell script that decodes to a typical shellcode loader. |
| T1083 File and Directory Discovery |
AutoIt backdoor is capable of identifying documents on the victim with the following extensions: .doc; .pdf, .csv, .ppt, .docx, .pst, .xls, .xlsx, .pptx, and .jpeg. |
| T1132.001 Standard Encoding |
AutoIt backdoor has sent a C2 response that was base64-encoded. |
| T1548.002 Bypass User Account Control |
AutoIt backdoor attempts to escalate privileges by bypassing User Access Control. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.