PULSE NAME
UAC0184 Steganography Based Remcos Campaign
WHITE cryptocti 2026-05-22 Modified: 2026-05-22
12
IOCs
MEDIUM VOLUME
UAC0184 runs a multi-stage phishing campaign using fake documents and shortcut files to trick users into execution. The attack abuses legitimate Windows tools like BITSAdmin and PowerShell to download and run malicious content. It uses steganography to hide malware inside image files, which is then extracted by a loader.
Indicators of Compromise (1 / 12 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
IPv4 169.40.135.35 CC=US ASN=ASNone 2026-05-22