Hackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process
Attackers use AutoIt and an invoice-themed batch file to inject AsyncRAT into Microsoft-signed charmap.exe for stealthy remote access.
Point Wild Threat Intelligence documented a five-stage campaign starting with 'Right-click to open Invoice Details.bat' that launches hidden PowerShell, drops a renamed AutoIt interpreter and encrypted loader into a random Temp folder, and persists via a Startup-folder batch file. The loader decrypts AsyncRAT only in memory and injects it into the Microsoft-signed charmap.exe (Windows Character Map) process, leaving no payload file on disk. The final payload patches AMSI inside the infected process and includes screen-capture code that prepares images for transfer to a command-and-control server at 158[.]51[.]122[.]136:4944.
- Invoice-themed batch file launches hidden PowerShell and AutoIt loader chain
- AsyncRAT runs in memory inside Microsoft-signed charmap.exe to evade detection
- Startup-folder batch file enables persistence without admin rights or Registry keys
- AMSI patched in-process; screen capture sent to C2 at 158.51.122.136:4944
Full article856 words · extracted from cybersecuritynews.com · click to collapse
Hackers are using a familiar Windows automation tool to hide AsyncRAT, a remote-access trojan, inside a trusted system process.
The campaign starts with a deceptive batch file named “Right-click to open Invoice Details.bat,” which can appear harmless to someone expecting an invoice or shared document.
Once opened, the file quietly launches PowerShell, rebuilds hidden code from fragments, and places several components in a random folder under the user’s temporary files.
The final goal is to give an attacker remote control while making the activity harder for both the victim and security software to spot.
Point Wild Threat Intelligence identified the five-stage chain and found that it ends with AsyncRAT running in memory within Windows Character Map, or charmap.exe.
Point Wild said in a report shared with Cyber Security News (CSN) that this is a Microsoft-signed Windows component, so its presence may look routine unless defenders inspect its parent process and memory.
The case shows how attackers combine social engineering, built-in scripting, and trusted programs rather than relying on one obvious malicious file.
Similar AutoIT malware delivery campaigns show why a file’s apparent legitimacy or a valid signature alone should not decide whether it is safe.
Hackers Abuse AutoIt
The infection begins after a victim manually opens the batch file, often following an email attachment, a malicious link, a trojanized download, or a file received through a messaging platform.
It launches PowerShell with its window hidden, disables the normal profile, and decodes a payload using Base64 text, inserted junk characters, and XOR operations.
.webp)
That stage drops a renamed, legitimate AutoIt interpreter, the loader script kojuyn.ini, and an extensionless encrypted file into a randomly named Temp directory.
It also writes h73la8.bat to the user’s Startup folder, allowing the pair to restart at each sign-in without needing administrator rights or a Registry run key. The loader decrypts its payload only in memory.
It then starts the 32-bit Character Map program invisibly and uses Windows programming functions to allocate memory, copy in the payload, and create a new thread to run it. The result is a malicious .NET program implanted in charmap.exe with no matching file left on disk.
This technique shifts suspicious network traffic and credential-access activity into a signed Windows process, a pattern also seen in process injection defense evasion cases that can frustrate checks focused only on executable names.
Screen Capture and Detection Priorities
After the injection step, the decrypted final DLL, Veukuzmw.dll, provides the familiar remote-access features associated with AsyncRAT.
Researchers observed screen-capture code that grabs the primary display, converts the image into bytes, and prepares it for storage or transfer to the operator’s command-and-control server.
The analysis also found AMSI, Windows’ script-scanning interface, patched inside the infected process. That detail matters because the malicious code is not merely disguised as a normal program.
It is designed to reduce the visibility of later script and assembly activity while its loader exits and leaves charmap.exe behind.
.webp)
Because charmap.exe is normally a simple utility for viewing special characters, it rarely needs to be launched hidden from an AutoIt process or make an outbound connection. Those unusual relationships are more valuable detection signals than the signed file alone.
Defenders should treat a hidden PowerShell process that writes files into Temp and Startup as a high-priority event, especially when it launches an AutoIt binary with a script-like file as its only argument.
Correlating that activity with unexpected charmap.exe launches, remote-thread creation, or network connections can expose the chain before data is taken.
Users should be wary of unexpected invoice files and avoid opening attachments, links, cracked software, or shared documents from unverified sources.
Teams can also use the lessons from AsyncRAT fileless loader techniques and recent AsyncRAT delivery campaigns to hunt for hidden scripting, startup persistence, and trusted processes behaving outside their normal role.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Filename / SHA-256 | Right-click to open Invoice Details.batae4144ff75a9b6371fd4d0ce0cce0e1d7be82f3c28eeea62ed5b9b0bea3 | Initial socially engineered batch-file lure and reported hash |
| Filename / SHA-256 | kojuyn.ini4affb923504ddf5fdd5f4a1185bf5259110bcf96cc3f0c740e7cf217bfb89a | AutoIt loader script and reported hash |
| Filename / SHA-256 | 3200000.exe22678bf501fee4baeef297bd2f122ea3cbcb99c8a525b0b30ab985bc8e3 | Recovered injected-stage executable and reported hash |
| Filename / SHA-256 | 3200000_02C37000.exe15700817e517fefcabc0291e350daf3e10d52f6b24de07b4e2396843a671 | Later recovered payload stage and reported hash |
| Filename / SHA-256 | Veukuzmw.dll61056e4c274694ca2553e715c93dc2768def716de750598d99df79252b | Final AsyncRAT DLL payload and reported hash |
| Filename | ogftogcyiblzjccmcbnw.exe | Renamed legitimate AutoIt interpreter used to launch the loader |
| Filename | nloemfbihmhm | Extensionless encrypted payload read and decrypted by the AutoIt loader |
| Filename | h73la8.bat | Startup-folder persistence batch file |
| C2 IP address and port | 158[.]51[.]122[.]136:4944 | AsyncRAT command-and-control endpoint observed in the analysis |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/hackers-inject-asyncrat/