Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. AuTo Stealer

AuTo Stealer

AuTo Stealer is malware written in C++ has been used bySideCopy since at least December 2021 to target government agencies and personnel in India and Afghanistan.[1]

ID: S1029
Type: MALWARE
Platforms: Windows
Version: 1.0
Created: 07 August 2022
Last Modified: 16 April 2025
Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1071.001Application Layer Protocol:Web Protocols

AuTo Stealer can use HTTP to communicate with its C2 servers.[1]

EnterpriseT1547.001Boot or Logon Autostart Execution:Registry Run Keys / Startup Folder

AuTo Stealer can place malicious executables in a victim's AutoRun registry key or StartUp directory, depending on the AV product installed, to maintain persistence.[1]

EnterpriseT1059.003Command and Scripting Interpreter:Windows Command Shell

AuTo Stealer can usecmd.exe to execute a created batch file.[1]

EnterpriseT1005Data from Local System

AuTo Stealer can collect data such as PowerPoint files, Word documents, Excel files, PDF files, text files, database files, and image files from an infected machine.[1]

EnterpriseT1074.001Data Staged:Local Data Staging

AuTo Stealer can store collected data from an infected host to a file namedHostname_UserName.txt prior to exfiltration.[1]

EnterpriseT1041Exfiltration Over C2 Channel

AuTo Stealer can exfiltrate data over actor-controlled C2 servers via HTTP or TCP.[1]

EnterpriseT1095Non-Application Layer Protocol

AuTo Stealer can use TCP to communicate with command and control servers.[1]

EnterpriseT1518.001Software Discovery:Security Software Discovery

AuTo Stealer has the ability to collect information about installed AV products from an infected host.[1]

EnterpriseT1082System Information Discovery

AuTo Stealer has the ability to collect the hostname and OS information from an infected host.[1]

EnterpriseT1033System Owner/User Discovery

AuTo Stealer has the ability to collect the username from an infected host.[1]

Groups That Use This Software

IDNameReferences
G1008SideCopy

References

×

[8]ページ先頭

©2009-2026 Movatter.jp