PULSE NAME
UAC0184 Steganography Based Remcos Campaign
WHITE cryptocti 2026-05-22 Modified: 2026-05-22
12
IOCs
MEDIUM VOLUME
UAC0184 runs a multi-stage phishing campaign using fake documents and shortcut files to trick users into execution. The attack abuses legitimate Windows tools like BITSAdmin and PowerShell to download and run malicious content. It uses steganography to hide malware inside image files, which is then extracted by a loader.
Indicators of Compromise (1 / 12 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 901d1dbb7a41569d2c5093f41a8194818aba695f SHA1 of df6942dc1a89226359adf1aac597c3b270f4a408214b4f7c2083f9524605e0f7 2026-05-22