AHK RAT Loader Delivers a Plethora of RATs

AutoHotKey (AHK) scripts are meant to help users automated certain tasks with the use of pre-made scripts. These scripts come in the form of an '.ahk' file, and they are executed with the use of an interpreter called AutoHotKey. However, it seems that cybercriminals have started to abuse this useful feature in order to deploy and execute malicious software. Since February 2021, cybersecurity experts have been observing an ongoing campaign, which leverages malicious AHK scripts to deploy a wide range of Remote Access Trojans (RATs.)

The AHK scripts abused by the criminals come with some fancy features such as the ability to bypass User Account Control (UAC,) disable Windows Defender, bypass virtual machines, and more. It is not clear how the final AHK file is delivered to victims, but there is a chance that the operators of the campaign might be abusing more than one propagation strategy. For example, they might be uploading malicious AHK scripts to legitimate repositories, therefore exploiting random victims. It is also possible that they might be approaching victims via fake downloads, fraudulent email attachments, and other shady content that delivers both the AHK interpreter, and the malicious script itself.

Some of the RAT families that the AHK RAT Loader campaign has been using are Vjw0rm, WSHRAT, AsyncRAT, and LimeRAT. What is peculiar about the delivery method is that the malicious executable was often packed with multiple legitimate installers – this is probably a basic attempt to throw off antirust tools and security services. Apart from the payloads, the AHK RAT Loader also executes AHK scripts dedicated to turning off Windows Defender. A similar loader also made the news recently - Snip3 Loader Empowers Large-scale RAT Attack Campaigns.

While cybercrime gangs rely on various methods to bypass UAC, Windows Defender, and other simple security measures, this is one of the first campaigns to do so with the abuse of AHK scripts. The AHK RAT Loader is currently detected by reputable antivirus software, and you can rest assured that your system is not in danger if you have protected it by up-to-date anti-malware software.

May 18, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.