threat-intel AutoIT Payload Injector , (Tue, Jul 28th) A wave of emails containing RAR archives containing AutoIT scripts are delivering a VIPKeylogger malware. The AutoIT scripts use legitimate tools like `charmap.exe` to inject and execute the malware, leveraging AutoIT's ability to call any API. The malware communicates with a command-and-control server and establishes… SANS Internet Storm Center · Jul 28, 2026 High autoitshellcodepersistence