{"id":2800,"date":"2021-05-21T22:41:40","date_gmt":"2021-05-22T03:41:40","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2800"},"modified":"2021-05-21T22:41:41","modified_gmt":"2021-05-22T03:41:41","slug":"ahk-the-new-malicious-rat-distribution-campaign","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/ahk-the-new-malicious-rat-distribution-campaign\/","title":{"rendered":"AHK, the new malicious RAT distribution campaign"},"content":{"rendered":"\n<p>An ongoing malware campaign has been discovered that uses the AutoHotkey (AHK) scripting language to deliver multiple RATs, such as LimeRAT, AsyncRAT, Houdini, Vjw0rm, and Revenge RAT. This campaign is unique in that it heavily uses the AutoHotKey scripting language, a fork of the AutoIt language often used for testing.<\/p>\n\n\n\n<p>According to Morphisec Labs researchers, the RAT delivery campaign begins with a compiled AHK script. The script includes the AHK interpreter, the script, and any files that you added using the FileInstall command.<\/p>\n\n\n\n<p><strong><em>\u25b8In the first variant of the attack<\/em><\/strong><\/p>\n\n\n\n<p>First seen on February 17, the attackers encapsulated the deleted RAT with an AHK executable and disabled Microsoft Defender with the Batch script and a shortcut file (.LNK) pointing to that script.<\/p>\n\n\n\n<p><strong><em>\u25b8The second version <\/em><\/strong><\/p>\n\n\n\n<p>First appeared on March 31 blocked connections to antivirus solutions by altering the victim&#8217;s host file. This manipulation negated DNS resolution for those domains by resolving the IP address of the local host instead of the real one.<\/p>\n\n\n\n<p><strong><em>\u25b8The third chain attack<\/em><\/strong><\/p>\n\n\n\n<p>First detected on April 8, delivered LimeRAT via obfuscated VBScript, which is then decoded into a PowerShell command that retrieves a C # payload.<\/p>\n\n\n\n<p><strong><em>\u25b8The fourth attack chain <\/em><\/strong><\/p>\n\n\n\n<p>Used an AHK script to run a genuine application, before delivering a VBScript that runs an in-memory PowerShell script to get the HCrypt loader and install AsyncRAT.<\/p>\n\n\n\n<p>The Morphisec researchers attributed all the different attack chains to the same threat actor, citing similarities in the AHK script and overlaps in the techniques used to disable Microsoft Defender.<\/p>\n\n\n\n<p>This is not the first time that AutoHotKey has been abused by attackers to remove malware. In December 2020, Trend Micro researchers discovered a credential stealer written in the AutoHotKey programming language that highlighted financial institutions in the United States and Canada.<\/p>\n\n\n\n<p>By using the AHK scripting language, attackers can hide their intent from sandboxes. In addition, the recent campaign uses innovative techniques to distribute various malicious programs. Obviously, this is not the only threat that we can find on the web, but it is important to be prepared to face these threats.<\/p>\n\n\n\n<p>See also:<br><a href=\"https:\/\/truxgoservers.com\/blog\/rat-is-a-very-dangerous-malware\/\">RAT is a very Dangerous Malware<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/hijacking-is-a-dangerous-type-of-cyberattack\/\">Hijacking is a dangerous type of Cyberattack<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An ongoing malware campaign has been discovered that uses the AutoHotkey (AHK) scripting language to deliver multiple RATs, such as LimeRAT, AsyncRAT, Houdini, Vjw0rm, and Revenge RAT. This campaign is unique in that it heavily uses the AutoHotKey scripting language, a fork of the AutoIt language often used for testing. According to Morphisec Labs researchers, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2801,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-2800","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>AHK, the new malicious RAT distribution campaign - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Malware campaigns have always been active and today we have to see one that relies heavily on the AutoHotkey (AHK) scripting language.....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/ahk-the-new-malicious-rat-distribution-campaign\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"AHK, the new malicious RAT distribution campaign - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Malware campaigns have always been active and today we have to see one that relies heavily on the AutoHotkey (AHK) scripting language.....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/ahk-the-new-malicious-rat-distribution-campaign\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-05-22T03:41:40+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-05-22T03:41:41+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/RAT-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"574\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ahk-the-new-malicious-rat-distribution-campaign\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ahk-the-new-malicious-rat-distribution-campaign\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"AHK, the new malicious RAT distribution campaign\",\"datePublished\":\"2021-05-22T03:41:40+00:00\",\"dateModified\":\"2021-05-22T03:41:41+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ahk-the-new-malicious-rat-distribution-campaign\\\/\"},\"wordCount\":364,\"commentCount\":3,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ahk-the-new-malicious-rat-distribution-campaign\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/RAT-1.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ahk-the-new-malicious-rat-distribution-campaign\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ahk-the-new-malicious-rat-distribution-campaign\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ahk-the-new-malicious-rat-distribution-campaign\\\/\",\"name\":\"AHK, the new malicious RAT distribution campaign - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ahk-the-new-malicious-rat-distribution-campaign\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ahk-the-new-malicious-rat-distribution-campaign\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/RAT-1.jpg\",\"datePublished\":\"2021-05-22T03:41:40+00:00\",\"dateModified\":\"2021-05-22T03:41:41+00:00\",\"description\":\"Malware campaigns have always been active and today we have to see one that relies heavily on the AutoHotkey (AHK) scripting language.....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ahk-the-new-malicious-rat-distribution-campaign\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ahk-the-new-malicious-rat-distribution-campaign\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ahk-the-new-malicious-rat-distribution-campaign\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/RAT-1.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/RAT-1.jpg\",\"width\":1000,\"height\":574},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ahk-the-new-malicious-rat-distribution-campaign\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AHK, the new malicious RAT distribution campaign\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"AHK, the new malicious RAT distribution campaign - Truxgo Server Blog","description":"Malware campaigns have always been active and today we have to see one that relies heavily on the AutoHotkey (AHK) scripting language.....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/ahk-the-new-malicious-rat-distribution-campaign\/","og_locale":"es_MX","og_type":"article","og_title":"AHK, the new malicious RAT distribution campaign - Truxgo Server Blog","og_description":"Malware campaigns have always been active and today we have to see one that relies heavily on the AutoHotkey (AHK) scripting language.....","og_url":"https:\/\/truxgoservers.com\/blog\/ahk-the-new-malicious-rat-distribution-campaign\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-05-22T03:41:40+00:00","article_modified_time":"2021-05-22T03:41:41+00:00","og_image":[{"width":1000,"height":574,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/RAT-1.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/ahk-the-new-malicious-rat-distribution-campaign\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/ahk-the-new-malicious-rat-distribution-campaign\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"AHK, the new malicious RAT distribution campaign","datePublished":"2021-05-22T03:41:40+00:00","dateModified":"2021-05-22T03:41:41+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/ahk-the-new-malicious-rat-distribution-campaign\/"},"wordCount":364,"commentCount":3,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/ahk-the-new-malicious-rat-distribution-campaign\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/RAT-1.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/ahk-the-new-malicious-rat-distribution-campaign\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/ahk-the-new-malicious-rat-distribution-campaign\/","url":"https:\/\/truxgoservers.com\/blog\/ahk-the-new-malicious-rat-distribution-campaign\/","name":"AHK, the new malicious RAT distribution campaign - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/ahk-the-new-malicious-rat-distribution-campaign\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/ahk-the-new-malicious-rat-distribution-campaign\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/RAT-1.jpg","datePublished":"2021-05-22T03:41:40+00:00","dateModified":"2021-05-22T03:41:41+00:00","description":"Malware campaigns have always been active and today we have to see one that relies heavily on the AutoHotkey (AHK) scripting language.....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/ahk-the-new-malicious-rat-distribution-campaign\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/ahk-the-new-malicious-rat-distribution-campaign\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/ahk-the-new-malicious-rat-distribution-campaign\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/RAT-1.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/RAT-1.jpg","width":1000,"height":574},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/ahk-the-new-malicious-rat-distribution-campaign\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"AHK, the new malicious RAT distribution campaign"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2800","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2800"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2800\/revisions"}],"predecessor-version":[{"id":2819,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2800\/revisions\/2819"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2801"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2800"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2800"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2800"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}