Activity timeline
T1218.005 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 12 reports, and 37 of the 37 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1218.005 Mshta is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of T1218 System Binary Proxy Execution. Threadlinqs maps 37 of 2623 tracked threats (1.4%) to it; by severity that is 2 critical, 34 high, 1 medium.
Threats that use T1218.005 most often also use T1059.001 PowerShell (30 threats), T1071.001 Web Protocols (29 threats), T1140 Deobfuscate/Decode Files or Information (28 threats), T1027 Obfuscated Files or Information (26 threats), T1082 System Information Discovery (26 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
20 tracked threat actors appear in the threats that use T1218.005; the most frequent are APT43 (3), Gamaredon (3), Kimsuky (3), APT-C-60 (2), MuddyWater (2).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1218.005.
Data sources
Telemetry that can reveal T1218.005, per MITRE ATT&CK.
- Command — Command Execution
- File — File Creation
- Network Traffic — Network Connection Creation
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 37 tracked threats that use T1218.005.
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)high
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and…high
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…high
- PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network…high
- Blockchain-Based C2 Evolution: Nation-State Actors Adopt Smart-Contract C2 (EtherHiding…high
- APT-C-60 Spear-Phishing Campaign Delivering SpyGlace via Proton Drive, RAR/LNK and Legitimate Developer…high
- Malware on the Blockchain: EtherHiding/Amatera ClickFix Campaign Adds a Covert WebRTC C2 Channelhigh
- Hundreds of WordPress Sites Hijacked via Malicious Plugins to Deploy Amatera Stealer through EtherHiding and…high
- Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers…high
- DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in Browser Cache Images via Steganographyhigh
- AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams…high
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiledhigh
- Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar…high
- Kimsuky Group Impersonates Diplomats to Deploy PebbleDash Backdoor and PrxClient Proxy (CVE-less LNK Campaign)high
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domainsmedium
- ACR Stealer (Amatera Stealer) Uses ClickFix Lures, WebDAV/pushd DLL Delivery, and EtherHiding to Harvest…high
- UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant in Financially Motivated Campaignhigh
- UAT-11795 (Russian) Trojanizes WebEx, Zoom, MobaXterm, DBeaver, FaceIT Installers to Deploy Starland RAT and…high
- SpyGlace Malware Campaign by APT-C-60 (Naikon) Abuses Trusted Developer Services (GitHub, GitLab, jsDelivr…high
- Domestic APT Spear-Phishing Campaigns (May 2026) — LNK/HTA/CHM/JSE Loaders Deploying XenoRAT, Suspected…high
- Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…high
- Remcos RAT: Technical Analysis of Windows Remote Access Trojan Operationshigh
- Gamaredon Expands Ukraine Attacks with PteroSetup Revival and Cloud Service Abuse, Exploiting WinRAR Flaw…high
- DeceptionAds: Fake CAPTCHA Malvertising Campaign Abusing the Monetag Ad Network to Distribute Lumma…high
- Internet Explorer WebBrowser Control Attack Chain — Two-Click RCE via Zone/MOTW Bypass and ActiveX COM…high
- Operation XENOFISCAL — SideCopy (Transparent Tribe / APT36 umbrella) Deploys Persistent Customized XenoRAT…high
- Cloud Atlas APT — termsrv.dll Byte-Patch for Multi-Session RDP, PowerCloud/PowerShower/VBCloud Chain…high
- InstallFix Campaign — Fake Claude AI Installer via Google Ads Drops mshta/ZIP-HTA Polyglot, AMSI-Bypass…high
- EtherRAT — Node.js Backdoor with Ethereum Blockchain C2 (EtherHiding) Linked to DPRK Contagious Interviewcritical
- SmartApeSG ClickFix Campaign Delivers Remcos RAT via Fake CAPTCHA Pageshigh
Detection coverage
Threadlinqs maintains 101 detection rules mapped to T1218.005 (SPL 41, KQL 32, Sigma 28). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1218 System Binary Proxy Execution — 170 tracked threats at the technique level.