
A new threat has emerged, in which malicious hackers are using AutoHotkey scripts to attack their victims and evade detection to steal information and install more payloads. They are also using TeamViewer to gain remote access to infected devices.
AutoHotkey, also known as AHK, is an open source programming language for Windows, created in 2003, which adds keyboard shortcut (hotkey) support to AutoIt, another Windows automation language.
The malicious AutoHotkey payload is installed via an attachment to an email sent to the victim, which is named Military Financing.xlsm, named after the Foreign Military Financing (FMF) program of the U.S. Defense Security Cooperation Agency, to trick potential targets into activating macros that will display the contents of the file.
As discovered by Trend Micro's Cyber Threat Research team, once victims enable macros in Microsoft Excel, the XSLM document will install malware on the victim's device.
According to researchers, the malicious AutoHotkeyU32.ahk script follows the following process:
- It creates a shortcut file in the startup folder for AutoHotkeyU32.exe, thus allowing the attack to persist, even after the system is rebooted.
- It connects to the C&C server every 10 seconds to download, save and execute files containing the commands.
- It sends the serial number of the C drive, which allows the attacker to identify the victim.
Finally, as researchers found, one of the malicious scripts downloaded to the device also installs a copy of TeamViewer, making it possible for malicious actors to remotely access infected computers.
The motives behind this attack are unknown. Its purpose could potentially be espionage, as it targets victims who show some interest in Defense Security Cooperation Agency programs.
However, seemingly harmless AutoHotkey scripts can be used by malicious hackers to install any payload, from banking Trojans to coinminers and backdoors to more dangerous malware, ransomware or wipers.
AHK-related malware strains emerged in 2018
AutoHotkey-based malware began appearing in early 2018 in the form of various phishing tools, with several AHK malware samples discovered by the Ixia security research team.
This software is used for various malicious purposes, such as hijacking, cryptomining, etc
Another case of such software was discovered by the Cybereason Nocturnus research team, where an AHK-based malware strain, dubbed Fauxpersky, attempted to pass itself off as a legitimate copy of Kaspersky Antivirus.
