ATT&CKSoftwareAutoIt backdoor

AutoIt backdoor

S0129

Malware.View on attack.mitre.org

About this malware

AutoIt backdoor is malware that has been used by the actors responsible for the MONSOON campaign. The actors frequently used it in weaponized .pps files exploiting CVE-2014-6352. This malware makes use of the legitimate scripting language for Windows GUI automation with the same name.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1059.001
PowerShell

AutoIt backdoor downloads a PowerShell script that decodes to a typical shellcode loader.

T1083
File and Directory Discovery

AutoIt backdoor is capable of identifying documents on the victim with the following extensions: .doc; .pdf, .csv, .ppt, .docx, .pst, .xls, .xlsx, .pptx, and .jpeg.

T1132.001
Standard Encoding

AutoIt backdoor has sent a C2 response that was base64-encoded.

T1548.002
Bypass User Account Control

AutoIt backdoor attempts to escalate privileges by bypassing User Access Control.

Groups that use it2

Campaigns0

None recorded.

References1

  1. Forcepoint Monsoon Open source
    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.