216.73.216.6

Unmasking a Multi-Stage Loader: AutoIt Abuse Leading to Vidar Stealer Command-and-Control Communication

· Published 11/05/2026 11:49 · Modified 11/05/2026 19:27

Export JSON

Essential information

Published
11/05/2026 11:49
Modified
11/05/2026 19:27
Tags
2026-05-11 anti-analysis arkei autoit c2 communication credential-theft defense evasion information stealer multi-stage loader vidar
Related entities
5 observables, 20 techniques (mitre), 2 malware, 2 others

Description

A sophisticated multi-stage infection chain was identified through proactive threat hunting, beginning with the execution of MicrosoftToolkit.exe, a commonly abused hack tool. The attack employed file masquerading techniques, renaming a .dot file to .bat format to evade detection. The malware performed process discovery and attempted to terminate security-related processes before extracting payloads using extract32.exe. An -compiled executable (Replies.scr) functioned as a loader, processing an external encrypted payload file and establishing command-and-control communication with infrastructure associated with Stealer. The malware demonstrated advanced capabilities, including debugger detection and instrumentation callback queries. It targeted credentials, browser data, cryptocurrency wallets, and system information. Post-execution cleanup routines deleted artifacts and terminated processes to minimize forensic evidence and evade detection, significantly complicating incident res...

External references