Cisco Talos has observed a new version of Loda, a remote access trojan (RAT) written in AutoIT. This campaign appears to be targeting countries in South America, Central America and the U.S. Multiple persistence mechanisms have been employed to ensure Loda continues running on the infected host following reboots. Loda is a simple, yet effective, RAT that has matured over time. This RAT is a good example of how effective relatively simple techniques combined with basic obfuscation can be.”]
Source: https://blog.talosintelligence.com/2020/02/loda-rat-grows-up.html