AutoIt backdoor
MITRE ATT&CK: S0129 View on attack.mitre.org
Aliases: AutoIt backdoor
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:48:11
Targeted industries: government-and-public-sector financial-services defense-and-aerospace
Targeted regions: country_code:in country_code:pk
Context
AutoIt backdoor is malware that has been used by the actors responsible for the MONSOON campaign. The actors frequently used it in weaponized .pps files exploiting CVE-2014-6352. This malware makes use of the legitimate scripting language for Windows GUI automation with the same name.
Detection coverage
- 1 YARA rules
- 261 Sigma rules
Malware & tools used
- File and Directory Discovery (attack-pattern)
- Bypass User Account Control (attack-pattern)
- Standard Encoding (attack-pattern)
- PowerShell (attack-pattern)
Used by threat actors
Exploited vulnerabilities
- CVE-2014-6352 (vulnerability)
Detection rules
- VOLEXITY_Malware_Win_Iis_Shellsave (yara-rule)
Reports & references
- forcepoint.com — Forcepoint Security Labs Monsoon Analysis Report (report)
- MITRE ATT&CK — S0129 (report)