news.mlab.sh
4 results
threat-intel

AutoIT Payload Injector , (Tue, Jul 28th)

A wave of emails containing RAR archives containing AutoIT scripts are delivering a VIPKeylogger malware. The AutoIT scripts use legitimate tools like `charmap.exe` to inject and execute the malware, leveraging AutoIT's ability to call any API. The malware communicates with a command-and-control server and establishes…

SANS Internet Storm Center · Jul 28, 2026 High