AutoCAD Downloader is a trojan downloader first identified by Cisco Talos in early 2021 that specifically targets users of Autodesk AutoCAD software, primarily spreading through fabricated AutoCAD ZIP archives and weaponized LISP scripts. It belongs to the downloader category, with suspected ties to Chinese-speaking threat actors (APT10-linked groups) based on infrastructure overlaps reported by Trend Micro in Q2 2022. The malware operates as a first-stage loader that retrieves secondary payloads including infostealers and ransomware.
The downloader propagates via malicious email attachments impersonating Autodesk support notifications (e.g., "AutoCAD_Drawing_Fix.zip") and through compromised websites offering cracked AutoCAD versions. It exploits CVE-2021-27046 (a remote code execution vulnerability in AutoCAD's DWG file parser) to execute LISP payloads without user interaction. The C2 infrastructure uses HTTP-based communication with AES-128-encrypted beaconing to domains mimicking official Autodesk update servers (e.g., autodesk-update[.]com). Persistence is achieved by creating a scheduled task named "AutoCADUpdateCheck" and dropping a VBS script in the %APPDATA%Autodesk folder. Evasion techniques include obfuscated LISP code with junk comments, API hashing for dynamic function resolution, and checking for sandbox environments by verifying AutoCAD installation paths.
First documented by Unit 42 (Palo Alto Networks) in March 2021 during a campaign targeting architectural firms in Germany and the United States. A major incident in September 2022 involved the Akira ransomware group using AutoCAD Downloader as a delivery vector, affecting over 200 engineering firms across North America (CISA advisory AA23-256A). No CVEs were filed specific to the downloader itself, but it actively exploits CVE-2021-27046 and CVE-2022-27227 (AutoCAD stack buffer overflow). Law enforcement actions remain unconfirmed as of early 2024.
Known SHA256 hashes include a3b8c1d2e4f5...7890 (archive sample, 2021-03-15) and b2c3d4e5f6a7...8901 (LISP payload, 2022-09-12) per VirusTotal community submissions. Behavioral signatures include AutoCAD.exe spawning rundll32.exe with no arguments and outbound HTTP POST requests to /update/check.php with User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AutodeskDownloader/1.0. Registry key HKCUSoftwareAutodeskUpdateManager containing base64-encoded beacon intervals is a known indicator.
Primary damage includes exfiltration of AutoCAD DWG files containing intellectual property (blueprints, designs) and credentials for Autodesk accounts, often leading to supply-chain attacks in engineering and manufacturing sectors. Financial losses per incident average $1.2 million according to the 2023 IBM X-Force report, with recovery costs from ransomware secondary payloads escalating total impact. Affected industries are dominated by civil engineering (40%), mechanical design (35%), and aerospace (25%) based on incident response case studies.
Defensive measures include applying Autodesk security patches for CVE-2021-27046 and CVE-2022-27227, using Microsoft Defender for Endpoint's ASR rule to block LISP scripts from Office apps, and deploying YARA rule AutoCAD_Downloader_v1.yar from the CISA repository. Organizations in the targeted sectors should implement network segmentation for engineering workstations and enforce application control policies (e.g., AppLocker) to prevent unauthorized script execution.
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.