logo

UAC-0184 Malware Chain Uses bitsadmin and HTA Files for Gated Payload Delivery

ID: e9f0eb66-af3f-55d4-8072-4539a05effe5

STIX ID: report--e9f0eb66-af3f-55d4-8072-4539a05effe5

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-05-19

Date Updated: 2026-05-22

Author: Tushar Subhra Dutta

...
...

## Executive Summary The report documents a targeted, multi-stage APT campaign (attributed to UAC-0184) against Ukrainian, military-related targets that uses bitsadmin and HTA-based social engineering to deploy an encrypted payload bundle, DLL sideloading into signed Visual Studio binaries, and repurposes PassMark BurnInTest multicast/TCP channels for covert C2; it includes detailed IoCs and recommended detection indicators for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.