Sunday, June 1, 2025
HomeMalwareHackers Launching Obfuscated RAT & Spyware To Log Keystroke and Steal Passwords...

Hackers Launching Obfuscated RAT & Spyware To Log Keystroke and Steal Passwords from Windows Apps

Published on

SIEM as a Service

Follow Us on Google News

Researchers discovered a new malicious campaign that delivered Different payloads such as Agent Tesla spyware and Ave Maria RAT To steal username and password and log keystroke from various Windows applications.

Researchers believed that these versions of that turn spyware to RAT might be used to deploy more lucrative and destructive ransomware and powerful payload post-exploitation.

These payloads have complied with AutoIT, a scripting language that is intended to automate basic tasks in Windows GUI, which is abused by cybercriminals to obfuscate the malware binary to evade the detection.

- Advertisement - Google News

AutoIT obfuscation technique mainly used to bypass the spam filters and easy way to mount the malicious ISO files in the recent windows version.

Trend Micro detected this malware as trojan spy Negasteal or Agent Tesla ( TrojanSpy.Win32.NEGASTEAL.DOCGC), and remote access trojan (RAT) Ave Maria or Warzone (TrojanSpy.Win32.AVEMARIA.T).

Researchers believed that threat actors delivering this malware campaign via compromised webmail address.

Infection Process

Malspam emails are frequently used to delivering obfuscated malware and email body posed as shipment advisory and a financial document with attached .RAR file.

Once the victims download the attachment and extract the file, it drops AutoIT-obfuscated malware strains of Negasteal and  Ave Maria.

According to Trend Micro research,”  the AutoIT obfuscation technique has two layers: The actual malware binaries are obfuscated into AutoIT scripts (.au3), after which the scripts are compiled into an executable using an AutoIT compiler like Aut2Exe. “

This kind of in-depth obfuscation technique can be used to easily bypass the endpoint solution equipped with behavior-based detection using machine learning without any security solution.

Researchers also observed that Ave Maria RAT variant has delivered with more functions to perform UAC bypass and process tokens to elevate its privileges.

As a result of successful infection, Negasteal/Agent Tesla variants will log and monitor keystrokes, webcam and screen capture, as well as collect information saved on clipboards. 

It also steals the Username and passwords from various protocols such as HTTP, IMAP, POP3, SMTP, and Windows applications including Microsoft Outlook, Windows Messaging, Internet Explorer, Google Chrome, Foxmail, Thunderbird, Firefox.

“Ave Maria can also modify, drop, and create arbitrary files in a compromised system, as well as enumerate processes, files, directories, and drives. It is also able to terminate running processes, delete files, and uninstall itself”, Trend Micro said.

Indicators of Compromise (IoCs)

SHA-256 Hash

Bc077b31c61d61d5d077b68b7f0b110efe85d138
224f6e0c21145534ec2bab670bcb1b690c08a26d

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Attackers Exploit Microsoft Entra Billing Roles to Escalate Privileges in Organizational Environments

A startling discovery by BeyondTrust researchers has unveiled a critical vulnerability in Microsoft Entra...

Threat Actors Exploit Google Apps Script to Host Phishing Sites

The Cofense Phishing Defense Center has uncovered a highly strategic phishing campaign that leverages...

Dadsec Hacker Group Uses Tycoon2FA Infrastructure to Steal Office365 Credentials

Cybersecurity researchers from Trustwave’s Threat Intelligence Team have uncovered a large-scale phishing campaign orchestrated...

Beware: Weaponized AI Tool Installers Infect Devices with Ransomware

Cisco Talos has uncovered a series of malicious threats masquerading as legitimate AI tool...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Hackers Use AI-Generated Videos on TikTok to Spread Info-Stealing Malware

TrendMicro has uncovered a sophisticated campaign where threat actors are exploiting TikTok to distribute...

Novel Malware Evades Detection by Skipping PE Header in Windows

Researchers have identified a sophisticated new strain of malware that bypasses traditional detection mechanisms...

New Rust-Based InfoStealer Uses Fake CAPTCHA to Deliver EDDIESTEALER

A newly discovered Rust-based infostealer, dubbed EDDIESTEALER, has been uncovered by Elastic Security Labs,...