logo

UAC-0184 Uses Bitsadmin and HTA Files to Deliver Gated Malware

ID: 47353ef3-52c8-5a78-9828-02ce394cd461

STIX ID: report--47353ef3-52c8-5a78-9828-02ce394cd461

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Mayura Kathir

...
...

This report analyzes a UAC-0184 campaign that uses social-engineered LNK lures and a staged loader chain (bitsadmin -> HTA -> PowerShell -> ZIP) to deploy a heavily obfuscated payload bundle; attackers achieve persistence and stealth via DLL sideloading into signed binaries (e.g., VSLauncher.exe, PassMark Endpoint) and implement custom networking (repurposed multicast and TCP ports) for command-and-control. The analysis includes technical unpacking of shellcode that hides PE files inside PNG-like containers, details of runtime behavior (dumping, network services), and IoCs such as a staging IP, multicast/TCP ports, and multiple SHA-256 hashes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.