AutoIt backdoor

MITRE ATT&CK: S0129 View on attack.mitre.org

Aliases: AutoIt backdoor

Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:48:11

Targeted industries: government-and-public-sector financial-services defense-and-aerospace

Targeted regions: country_code:in country_code:pk

Context

AutoIt backdoor is malware that has been used by the actors responsible for the MONSOON campaign. The actors frequently used it in weaponized .pps files exploiting CVE-2014-6352. This malware makes use of the legitimate scripting language for Windows GUI automation with the same name.

Detection coverage

  • 1 YARA rules
  • 261 Sigma rules

Malware & tools used

  • File and Directory Discovery (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • Standard Encoding (attack-pattern)
  • PowerShell (attack-pattern)

Used by threat actors

Exploited vulnerabilities

  • CVE-2014-6352 (vulnerability)

Detection rules

  • VOLEXITY_Malware_Win_Iis_Shellsave (yara-rule)

Reports & references

  • forcepoint.com — Forcepoint Security Labs Monsoon Analysis Report (report)
  • MITRE ATT&CK — S0129 (report)

External references