AHK RAT Loader
Summary
Details about an ongoing attack campaign that drops RAT payloads onto compromised systems ultimately have been released by security researchers. According to their findings, the threat actor is using a unique AutoHotKey (AHK) compiled script as an initial stage loader. The AHK RAT Loader campaign has evolved rapidly in the months since it was launched with multiple distinct attack chains, each becoming sophisticated increasingly and attaining new functionalities. An attack chain that uses the AHK RAT Loader but exhibits certain deviations from the rest of the operations in this campaign delivered the AsyncRAT as its final payload. The observed modifications and the introduction of new techniques show the lasting efforts of the threat actor behind the AHK RAT Loader to avoid detection by passive security controls.