AutoHotKey & AutoIT

T1059.010

Sub-technique of T1059 Command and Scripting Interpreter.View on attack.mitre.org

About this technique

Adversaries may execute commands and perform malicious tasks using AutoIT and AutoHotKey automation scripts. AutoIT and AutoHotkey (AHK) are scripting languages that enable users to automate Windows tasks. These automation scripts can be used to perform a wide variety of actions, such as clicking on buttons, entering text, and opening and closing programs.

Adversaries may use AHK (`.ahk`) and AutoIT (`.au3`) scripts to execute malicious code on a victim's system. For example, adversaries have used for AHK to execute payloads and other modular malware such as keyloggers. Adversaries have also used custom AHK files containing embedded malware as Phishing payloads.

These scripts may also be compiled into self-contained executable payloads (`.exe`).

Detection rules0

Rules on DetectionCode tagged with T1059.010.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups1

Software5

Campaigns0

None recorded.

Procedure examples6

Groups1

Used byProcedure example
GroupAPT39

APT39 has utilized AutoIt malware scripts embedded in Microsoft Office documents or malicious links.

Software5

Used byProcedure example
MalwareDarkGate

DarkGate uses AutoIt scripts dropped to a hidden directory during initial installation phases, such as `test.au3`.

MalwareLumma Stealer

Lumma Stealer has utilized AutoIt malware scripts and AutoIt executables.

MalwareMelcoz

Melcoz has been distributed through an AutoIt loader script.

MalwareOutSteel

OutSteel was developed using the AutoIT scripting language.

MalwareXLoader

XLoader can use an AutoIT script to decrypt a payload file, load it into victim memory, then execute it on the victim machine.

References3

  1. AutoHotKey Open source
    AutoHotkey Foundation LLC. (n.d.). Using the Program. Retrieved March 29, 2024.
  2. AutoIT Open source
    AutoIT. (n.d.). Running Scripts. Retrieved March 29, 2024.
  3. Splunk DarkGate Open source
    Splunk Threat Research Team. (2024, January 17). Enter The Gates: An Analysis of the DarkGate AutoIt Loader. Retrieved March 29, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.