APTMembers
APT

Same AutoIT Toolkit Links 2021 Droppers to 2024 Excel Lures

A YARA rule for AutoIT scripting ties a 2021 dropper wave to an October 2024 Excel add-in campaign, exposing an operation that swaps its delivery vector while keeping its build toolkit intact. CTX Team's file analysis, tagged Operation Black Atlas, resolves into two build lineages, a Discord-CDN staging trick, and a narrow SingNet-hosted C2 pair — all feeding RedLine and ClipBanker credential theft.

Sep 26, 2026, 06:30 (UTC+9)Last seenSep 26, 2026Severity100ByCTX TeamActorOperation Black AtlasIOC32RegionsUS

A dropper wave built in mid-2021 and an Excel-lure campaign built in October 2024 have almost nothing in common on the surface — different file formats, different lure themes, three years of separation — except that both fire the same YARA rule for AutoIT scripting. That single recurring signature, tying a 2021 downloader (164e93724abba0dd…) to a 2024 Office add-in (7acc59a5ff51435e…), is the most durable thread running through a file set that CTX Team has been tracking under the tag Operation…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence