home.social

#autoit — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #autoit, aggregated by home.social.

fetched live
  1. June 2026 Threat Trend Report on APT Attacks (South Korea)

    AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.

    Pulse ID: 6a635bdf995351cf539c3b56
    Pulse Link: otx.alienvault.com/pulse/6a635
    Pulse Author: AlienVault
    Created: 2026-07-24 12:34:39

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault

  2. June 2026 Threat Trend Report on APT Attacks (South Korea)

    AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.

    Pulse ID: 6a635bdf995351cf539c3b56
    Pulse Link: otx.alienvault.com/pulse/6a635
    Pulse Author: AlienVault
    Created: 2026-07-24 12:34:39

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault

  3. Still Circling: Toolkit Keeps Evolving

    Between May and July 2026, researchers tracked the Latin America-focused threat actor Blind Eagle through multiple exposed staging servers, identifying significant toolkit evolution. Four key developments emerged: a third string-obfuscation scheme featuring JavaScript with custom AES S-box substitution, a RunPE loader using bare AutoIt3 interpreter staged via GitHub, a reusable 'Photo Studio' persistence mechanism shared across three distinct toolchains, and a materially upgraded AsyncRAT variant codenamed JC-46. This enhanced RAT incorporates Windows Notification Facility process injection, custom Base28 encoding, Hidden VNC banking-fraud capabilities with browser profile cloning, and a Chrome App-Bound Encryption v20 bypass. Despite operational security weaknesses including exposed directories and hardcoded credentials, the group demonstrates selective sophistication targeting banking operations across Spanish-speaking regions.

    Pulse ID: 6a5b639c3194d1cc5f0e281b
    Pulse Link: otx.alienvault.com/pulse/6a5b6
    Pulse Author: AlienVault
    Created: 2026-07-18 11:29:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AsyncRAT #Autoit #Bank #BlindEagle #Browser #Chrome #CyberSecurity #Encryption #GitHub #InfoSec #Java #JavaScript #LatinAmerica #OTX #OpenThreatExchange #RAT #VNC #Windows #bot #AlienVault

  4. Still Circling: Toolkit Keeps Evolving

    Between May and July 2026, researchers tracked the Latin America-focused threat actor Blind Eagle through multiple exposed staging servers, identifying significant toolkit evolution. Four key developments emerged: a third string-obfuscation scheme featuring JavaScript with custom AES S-box substitution, a RunPE loader using bare AutoIt3 interpreter staged via GitHub, a reusable 'Photo Studio' persistence mechanism shared across three distinct toolchains, and a materially upgraded AsyncRAT variant codenamed JC-46. This enhanced RAT incorporates Windows Notification Facility process injection, custom Base28 encoding, Hidden VNC banking-fraud capabilities with browser profile cloning, and a Chrome App-Bound Encryption v20 bypass. Despite operational security weaknesses including exposed directories and hardcoded credentials, the group demonstrates selective sophistication targeting banking operations across Spanish-speaking regions.

    Pulse ID: 6a5b639c3194d1cc5f0e281b
    Pulse Link: otx.alienvault.com/pulse/6a5b6
    Pulse Author: AlienVault
    Created: 2026-07-18 11:29:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AsyncRAT #Autoit #Bank #BlindEagle #Browser #Chrome #CyberSecurity #Encryption #GitHub #InfoSec #Java #JavaScript #LatinAmerica #OTX #OpenThreatExchange #RAT #VNC #Windows #bot #AlienVault

  5. The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

    Since late March 2026, a large-scale phishing campaign has been deploying malware including Agent Tesla, Remcos, XWorm, and Best Private LOGGER through fileless techniques and low-detection Lua-based loaders. Attackers impersonate well-known companies using business cooperation lures to distribute malicious archives containing obfuscated JavaScript files. These scripts deploy either AutoIt or LuaJIT interpreters alongside disguised scripts masquerading as TrueType Font (.ttf) files. The Lua loaders employ sophisticated anti-analysis techniques including custom ROT ciphers, decoy memory allocation, and Donut shellcode generation for reflective in-memory payload execution. The campaign evolved from simpler implementations in October 2025 to highly complex versions by June 2026, incorporating API unhooking and advanced debugging countermeasures. Victims are ultimately infected with Remote Access Trojans and infostealers that enable full system control and extensive data exfiltration.

    Pulse ID: 6a59018a415370b96937338d
    Pulse Link: otx.alienvault.com/pulse/6a590
    Pulse Author: AlienVault
    Created: 2026-07-16 16:06:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AgentTesla #Autoit #CyberSecurity #InfoSec #InfoStealer #Java #JavaScript #LUA #Malware #OTX #OpenThreatExchange #Phishing #RAT #Remcos #RemoteAccessTrojan #ShellCode #Tesla #Trojan #Worm #XWorm #bot #AlienVault

  6. The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

    Since late March 2026, a large-scale phishing campaign has been deploying malware including Agent Tesla, Remcos, XWorm, and Best Private LOGGER through fileless techniques and low-detection Lua-based loaders. Attackers impersonate well-known companies using business cooperation lures to distribute malicious archives containing obfuscated JavaScript files. These scripts deploy either AutoIt or LuaJIT interpreters alongside disguised scripts masquerading as TrueType Font (.ttf) files. The Lua loaders employ sophisticated anti-analysis techniques including custom ROT ciphers, decoy memory allocation, and Donut shellcode generation for reflective in-memory payload execution. The campaign evolved from simpler implementations in October 2025 to highly complex versions by June 2026, incorporating API unhooking and advanced debugging countermeasures. Victims are ultimately infected with Remote Access Trojans and infostealers that enable full system control and extensive data exfiltration.

    Pulse ID: 6a59018a415370b96937338d
    Pulse Link: otx.alienvault.com/pulse/6a590
    Pulse Author: AlienVault
    Created: 2026-07-16 16:06:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AgentTesla #Autoit #CyberSecurity #InfoSec #InfoStealer #Java #JavaScript #LUA #Malware #OTX #OpenThreatExchange #Phishing #RAT #Remcos #RemoteAccessTrojan #ShellCode #Tesla #Trojan #Worm #XWorm #bot #AlienVault

  7. Мой соавтор — DeepSeek

    Эта статья о моем опыте сотрудничества с DeepSeek в разработке некоторых поделок на различных языках программирования.Раньше писал на этих языках, но без помощи ИИ.

    habr.com/ru/articles/1010138/

    #искусственный_интеллект #autoit #lua # #gsm

  8. Мой соавтор — DeepSeek Эта статья о моем опыте сотрудничества с DeepSeek в разработке некоторых поделок на различн...

    #искусственный #интеллект #autoit #lua #cи #gsm

    Origin | Interest | Match
  9. Und jetzt die Preisfrage:
    Wieso um alles in der Welt habe ich für den ganzen Mist "AutoIT" verwendet, welches ich für ein super tool halte aber für diesen Task eigendlich das falsche Werkzeug?

    Aus dem wichtigsten Grund der Toolauswahl: Ich kann damit umgehen.

    9/9

    #programmieren #AutoIT #VM #storytime

  10. CryptoWire ransomware with decryption key

    This report provides an analysis of the CryptoWire ransomware, an open-source malware initially spread in 2018 via phishing emails. The malware is written in Autoit and contains the decryption keys within the code, allowing files to be decrypted without payment. It encrypts files and leaves a ransom note demanding payment, but does not actually require payment due to the presence of the keys.

    Pulse ID: 65f0719757d7545ff215174d
    Pulse Link: otx.alienvault.com/pulse/65f07
    Pulse Author: AlienVault
    Created: 2024-03-12 15:15:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #RansomWare #Malware #RCE #Phishing #Email #Autoit #AlienVault

  11. 💡 #TIL there's another effort going on to bring inglorious

    #AutoHotkey to 🐧 GNU/‬#Linux!
    (#X11, that is.)

    Meet #AHK_X11 🥳

    🌐 github.com/phil294/AHK_X11
    📖 phil294.github.io/AHK_X11

    ☝️ Caveat: It only supports legacy #AHK 1.1 syntax and does not aim for 100% feature parity/compatibility, but should enable you to use most of your #hotkeys and #hotstrings #crossplattform! (Sync on your own).

    #scripting #automation #DesktopAutomation #KeyboardWarriors #xdotool #gtk #AutoIt #AutoKey #AlternativeTo

  12. 💡 #TIL there's another effort going on to bring inglorious

    #AutoHotkey to 🐧 GNU/‬#Linux!
    (#X11, that is.)

    Meet #AHK_X11 🥳

    🌐 github.com/phil294/AHK_X11
    📖 phil294.github.io/AHK_X11

    ☝️ Caveat: It only supports legacy #AHK 1.1 syntax and does not aim for 100% feature parity/compatibility, but should enable you to use most of your #hotkeys and #hotstrings #crossplattform! (Sync on your own).

    #scripting #automation #DesktopAutomation #KeyboardWarriors #xdotool #gtk #AutoIt #AutoKey #AlternativeTo

  13. @nixCraft I was 14 and I was trying to make a program to backup my Minecraft world saves 😅

    Before that I had unsuccessfully attempted to learn #python, it never clicked to me. Everyone said that the syntax was easy but it wasn't easy for me.

    What did click with me was Windows Shell Script, a.k.a Batch!

    I felt very powerful when I started writing my little batch scripts. Soon after I discovered an obscure language called #AutoIt which I loved! I still use it to this day, professionally too.

  14. Well, here goes: #introduction

    It started with Apple IIs and Oregon Trail in the late 80s, and in middle school they had a lab full of them and we drew stuff with LOGO and saved our work on the old 5 inch floppies. Was addicted to Hover when it came out. Finally we had a family computer and got dialup, and I was home alone when I experienced my first malware infection, and not wanting to get in trouble, I learned really fast what the command line and the registry were, and I had it all cleaned up with no trace by the time anyone else got home. I'd spend hours tinkering with this or that, or fixing things that went wrong.

    Discovered AI/chatbots and built a couple using the Personality Forge, and for a while they were the most advanced chatbots on the site. I'd work on their programming with a Palm IIIe and a folding keyboard, while away from my desk, and then I'd 'hotsync' my notes and upload changes via dialup, those were the days! "Get off the computer I need to make a phone call" lol

    My interests were anything tech. It went from being an interest to being a professional endeavor when I started doing flash dev and website work for a travel directory site in PV, Mexico, while I was living there, and when I returned to the states I worked for a small ISP doing #WIMAX installs using Motorola Canopy gear, along with whatever malware removal, hardware fixes, repairs, reinstalls, whatever, all manner of PC stuff.

    Moved to TX, worked for another ISP down there doing the same thing, involved using slightly older tech gear, and this was around the time malware infections were starting to really plague even smaller businesses, and I started to focus on #infosec and #security, and then they bought a webhosting company and I switched back to website work, updating sites that had been built using... html tables and sketchy code that was often missing tags. Wrote repair articles for #Technibble for a while, then started out on my own, specializing in anything tech, from #networking #troubleshooting #ComputerRepair #programming small stuff using batch scripts, #AutoIT, (am I supposed to tag this stuff? I'm new to this here) and started up my own #webhosting company where I could pick and choose what platforms to use, free reign to give customers the best bang for their buck, and #WordPress was simple enough to get them into, make something that fit the need, and then hand the reins over to them for most of the content changes in the future unless something went terribly wrong.

    Worked in retail electronics and got some experience with mobile tech, helped customers with analog phones transfer their stuff to new phones, activation, etc, meanwhile discovering Android, which led to #root discovery and fascination with #CustomRom stuff, which led to #AppDev for a customer using Android and iOS, but I only dabble in that sector.

    Returned to WA and helped with a non-tech family business, but the lack of a #CRM that did what I wanted led me to build custom functionality onto an existing CRM using the ol' #php, and then built a custom #IoT system using #micropython for a customer, #ESP32 (love these things) etc, and then the pandemic happened and I went straight into #python and wanted to use #django but the workflow wasn't to my liking, so I took a step back and followed a friend's advice to get more into #javascript which I'm absolutely loving, with a focus on #NodeJS.

    My main line of work at the moment is something I'd probably have to add a disclaimer for, so instead I'll just say that it's really fun and keeps me active, and involves tech to a degree, possibly primarily because I prefer to leverage tech solutions wherever possible to save time, money, and 'decision fatigue' to spend that instead on refreshing old skills and learning new ones.

    I type really fast, which unfortunately leads to me writing entire novels inside emails (heh) and I also forget a lot of the stuff I've done because I switch focus depending on what solutions are needed, so for a TL;DR:

    I'm a nerd who loves anything even lightly tech or security related, sort of a jack of all trades #technologist: If someone has a problem or a tech need, I either find an affordable/free solution or build it. If I need to learn it to build it, no worries, just adds a little time to the project.

    I love this #Mastodon thing and look forward to all the awesome stuff I've been seeing here, wishing I had more to share in return. Thank you @jerry!

  15. Die Regierung fördert die Branche mit dem Ziel, ihre Transformation voranzutreiben – beim autonomen Fahren, der Digitalisierung und alternativen Antrieben.
    Mobilitätswandel: Hilfsprogramm für Autozulieferer in Milliardenhöhe steht