Executive Summary
AuTo Stealer is a Windows credential stealer developed by SideCopy, targeting Indian and Afghan government personnel since late 2021. It harvests browser passwords, logs keystrokes, captures screenshots, and exfiltrates data via HTTPS to an adversary C2 server. The malware’s use against politically sensitive targets classifies it as a high‑risk nation‑state campaign.
Enhanced Description
AuTo Stealer is a Windows‑only malware written in C++ that has been actively used by the SideCopy threat actor since at least December 2021 to target government agencies and personnel in India and Afghanistan. The weaponization platform was uncovered by MalwareBytes, which identified it as a sophisticated credential‑stealing family that focuses on high‑profile political targets. The malware is engineered to harvest credentials from popular web browsers such as Chrome, Edge, and Firefox, while also capturing clipboard content and logging keystrokes. In addition, it can take full desktop screenshots, enumerate network shares, collect system inventory (OS version, installed applications), and persist by creating scheduled tasks or modifying registry Run keys. Collected data is exfiltrated to a command‑and‑control server over an encrypted HTTPS channel. The impact of a successful AuTo Stealer infection extends beyond the immediate loss of credentials; it provides adversaries with a foothold for lateral movement, data exfiltration, and potential sabotage within targeted institutions. Given its emphasis on government entities in politically sensitive regions, the threat is classified as a high‑impact nation‑state campaign.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The available public data provides a limited view of AuTo Stealer’s exact capabilities and infrastructure. While core behaviors align with common credential‑stealing families observed under SideCopy, specific details—such as precise C2 endpoint lists, persistence strategies beyond registry tweaks, and lateral movement mechanisms—remain undocumented. Consequently, confidence in the current intelligence is moderate; further internal analysis and IOC correlation are needed to fill these gaps.
AuTo Stealer is malware written in C++ has been used by SideCopy since at least December 2021 to target government agencies and personnel in India and Afghanistan.(Citation: MalwareBytes SideCopy Dec 2021)