UAC-0184 Uses Bitsadmin and HTA Files to Deliver Gated Malware
ID: 47353ef3-52c8-5a78-9828-02ce394cd461
STIX ID: report--47353ef3-52c8-5a78-9828-02ce394cd461
Feed Name: GBHackers
This report analyzes a UAC-0184 campaign that uses social-engineered LNK lures and a staged loader chain (bitsadmin -> HTA -> PowerShell -> ZIP) to deploy a heavily obfuscated payload bundle; attackers achieve persistence and stealth via DLL sideloading into signed binaries (e.g., VSLauncher.exe, PassMark Endpoint) and implement custom networking (repurposed multicast and TCP ports) for command-and-control. The analysis includes technical unpacking of shellcode that hides PE files inside PNG-like containers, details of runtime behavior (dumping, network services), and IoCs such as a staging IP, multicast/TCP ports, and multiple SHA-256 hashes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
