Product
AutoHotkey
- First Reported
- Jul 22, 2026
- Latest Reported
- Jul 22, 2026
Reported Context (1)
- access. Once connected, threat actors navigated to an Amazon S3-hosted phishing site and downloaded AutoHotkey along with a malicious AutoHotkey script, which was then executed to install Edgecution. UNC6692 Uses Email Bombing, IT Impersonation and Quick Assist to Deploy Edgecution
Malware (1)
Threat Actors (2)
MITRE ATT&CK (21)
Vendors (5)
Products (11)
Tools (2)
Industries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.