PULSE NAME
UAC0184 Steganography Based Remcos Campaign
WHITE cryptocti 2026-05-22 Modified: 2026-05-22
12
IOCs
MEDIUM VOLUME
UAC0184 runs a multi-stage phishing campaign using fake documents and shortcut files to trick users into execution. The attack abuses legitimate Windows tools like BITSAdmin and PowerShell to download and run malicious content. It uses steganography to hide malware inside image files, which is then extracted by a loader.
Indicators of Compromise (1 / 12 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 b0405f718860843883813541a5d886c3 MD5 of df6942dc1a89226359adf1aac597c3b270f4a408214b4f7c2083f9524605e0f7 2026-05-22