Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Use AutoIt to Conceal AsyncRAT in Windows

Hackers Use AutoIt to Conceal AsyncRAT in Windows

Posted on September 14, 2026 By CWS

Cybersecurity experts have uncovered a new method where attackers use a Windows automation tool to disguise AsyncRAT, a remote-access trojan, within a Windows-signed process. This tactic uses AutoIt to make the presence of the trojan less noticeable to users and security systems.

Deceptive Batch File Initiates Attack

The attack begins with a seemingly innocuous batch file labeled “Right-click to open Invoice Details.bat,” which tempts users into opening it. Once executed, this file covertly activates PowerShell, reassembling fragmented code and deploying components into a random temp folder. This strategy aims to establish remote control over the targeted system while minimizing detection risks.

Researchers from Point Wild Threat Intelligence traced this five-stage process, highlighting how it ultimately results in AsyncRAT executing within the Windows Character Map, or charmap.exe. As this is a Microsoft-signed component, its presence appears normal unless thoroughly inspected.

Complex Infection Process via AutoIt

The infection chain is initiated when a user opens the batch file, often delivered through email attachments, malicious links, or other vectors. This action triggers PowerShell to run silently, bypassing typical security checks, and decodes the payload using Base64 and XOR operations.

The infiltration continues as a legitimate AutoIt interpreter and other components are placed in a temporary directory, facilitating the execution of malicious code within charmap.exe. This technique shifts suspicious activities into a trusted Windows process, complicating detection efforts.

Security Implications and Defense Strategies

Once the trojan is active, it provides robust remote-access features, including screen capture capabilities, sending data to the operator’s server. The infection also modifies Windows’ script-scanning interface, AMSI, to conceal malicious activities.

Security teams are advised to monitor for unusual PowerShell activities and unexpected launches of charmap.exe. Such anomalies can indicate a compromised system, prompting further investigation to prevent data breaches.

Users should exercise caution with unexpected invoice files and avoid interactions with unverified links or attachments. Security teams can leverage insights from recent AsyncRAT incidents to enhance their threat detection and response strategies.

For comprehensive threat intelligence, security teams should keep their systems updated with the latest information on malware and phishing activities, utilizing platforms like ANYRUN for early detection and prevention.

Cyber Security News Tags:AsyncRAT, AutoIT, Cybersecurity, fileless malware, Malware, network security, PowerShell, process injection, remote access trojan, threat detection, Windows security

Post navigation

Previous Post: Urgent Alert on Check Point VPN Vulnerabilities
Next Post: Twitch Extension Security Breach Exposes OAuth Tokens

Related Posts

WordPress Urges Update to Fix Critical RCE Vulnerability WordPress Urges Update to Fix Critical RCE Vulnerability Cyber Security News
RenEngine Loader Bypasses Security with Multi-Stage Attack RenEngine Loader Bypasses Security with Multi-Stage Attack Cyber Security News
Threat Actors Leveraging GenAI for Phishing Attacks Impersonating Government Websites Threat Actors Leveraging GenAI for Phishing Attacks Impersonating Government Websites Cyber Security News
Cloudflare Confirms Data Breach, Hackers Stole Customer Data from Salesforce Instances Cloudflare Confirms Data Breach, Hackers Stole Customer Data from Salesforce Instances Cyber Security News
New Inboxfuscation Tool That Bypasses Microsoft Exchange Inbox Rules and Evade Detection New Inboxfuscation Tool That Bypasses Microsoft Exchange Inbox Rules and Evade Detection Cyber Security News
Fake AI Installers Exploit Users with Malware Fake AI Installers Exploit Users with Malware Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Patch Issued for ScreenConnect Vulnerability
  • Twitch Extension Security Breach Exposes OAuth Tokens
  • Hackers Use AutoIt to Conceal AsyncRAT in Windows
  • Urgent Alert on Check Point VPN Vulnerabilities
  • Critical Cybersecurity Updates: Microsoft, FortiOS, and More

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Patch Issued for ScreenConnect Vulnerability
  • Twitch Extension Security Breach Exposes OAuth Tokens
  • Hackers Use AutoIt to Conceal AsyncRAT in Windows
  • Urgent Alert on Check Point VPN Vulnerabilities
  • Critical Cybersecurity Updates: Microsoft, FortiOS, and More

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark