# T1218.005 Mshta

> As of 2026-10-05, T1218.005 (Mshta) appears in 37 tracked threats, first reported 2026-01-01 and most recently 2026-10-02, with linked actors including APT43, Gamaredon, Kimsuky; it most often appears alongside T1059.001 (PowerShell).

- **Tracked threats:** 37 (2 critical, 34 high, 1 medium)
- **First seen:** 2026-01-01
- **Last seen:** 2026-10-02
- **Threat actors:** 20
- **Detection rules:** 101 (counts only; Blue tier and above)

## Key facts

- **ID:** T1218.005
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1218
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1218/005/

## Activity timeline

T1218.005 first appeared in tracked threats on 2026-01-01 and was most recently reported on 2026-10-02. The busiest month was 2026-07 with 12 reports, and 37 of the 37 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1218.005 Mshta is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of [T1218 System Binary Proxy Execution](https://intel.threadlinqs.com/technique/T1218). Threadlinqs maps 37 of 2623 tracked threats (1.4%) to it; by severity that is 2 critical, 34 high, 1 medium.

Threats that use T1218.005 most often also use [T1059.001 PowerShell](https://intel.threadlinqs.com/technique/T1059.001) (30 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (29 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (28 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (26 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (26 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

20 tracked threat actors appear in the threats that use T1218.005; the most frequent are [APT43](https://intel.threadlinqs.com/actor/APT43) (3), [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) (3), [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) (3), [APT-C-60](https://intel.threadlinqs.com/actor/APT-C-60) (2), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (2).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1218.005.

- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)

## Data sources

Telemetry that can reveal T1218.005, per MITRE ATT&CK.

- Command — Command Execution
- File — File Creation
- Network Traffic — Network Connection Creation
- Process — Process Creation

## Threat actors using it

- [APT43](https://intel.threadlinqs.com/actor/APT43) — 3
- [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) — 3
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 3
- [APT-C-60](https://intel.threadlinqs.com/actor/APT-C-60) — 2
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 2
- [SideCopy](https://intel.threadlinqs.com/actor/SideCopy) — 2
- [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) — 2
- [APT29](https://intel.threadlinqs.com/actor/APT29) — 1
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 1
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca) — 1
- [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) — 1

## Tracked threats

The 30 most recent of 37 tracked threats that use T1218.005.

- [Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)](https://intel.threadlinqs.com/threat/TL-2026-2848) — high — 2026-10-02
- [AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and…](https://intel.threadlinqs.com/threat/TL-2026-2800) — high — 2026-09-30
- [Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…](https://intel.threadlinqs.com/threat/TL-2026-2764) — high — 2026-09-28
- [PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network…](https://intel.threadlinqs.com/threat/TL-2026-2527) — high — 2026-09-15
- [Blockchain-Based C2 Evolution: Nation-State Actors Adopt Smart-Contract C2 (EtherHiding…](https://intel.threadlinqs.com/threat/TL-2026-2484) — high — 2026-09-13
- [APT-C-60 Spear-Phishing Campaign Delivering SpyGlace via Proton Drive, RAR/LNK and Legitimate Developer…](https://intel.threadlinqs.com/threat/TL-2026-2371) — high — 2026-09-07
- [Malware on the Blockchain: EtherHiding/Amatera ClickFix Campaign Adds a Covert WebRTC C2 Channel](https://intel.threadlinqs.com/threat/TL-2026-2311) — high — 2026-09-03
- [Hundreds of WordPress Sites Hijacked via Malicious Plugins to Deploy Amatera Stealer through EtherHiding and…](https://intel.threadlinqs.com/threat/TL-2026-2214) — high — 2026-08-29
- [Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers…](https://intel.threadlinqs.com/threat/TL-2026-2120) — high — 2026-08-23
- [DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in Browser Cache Images via Steganography](https://intel.threadlinqs.com/threat/TL-2026-1847) — high — 2026-08-03
- [AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams…](https://intel.threadlinqs.com/threat/TL-2026-1777) — high — 2026-07-30
- [Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled](https://intel.threadlinqs.com/threat/TL-2026-1721) — high — 2026-07-27
- [Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar…](https://intel.threadlinqs.com/threat/TL-2026-1693) — high — 2026-07-25
- [Kimsuky Group Impersonates Diplomats to Deploy PebbleDash Backdoor and PrxClient Proxy (CVE-less LNK Campaign)](https://intel.threadlinqs.com/threat/TL-2026-1645) — high — 2026-07-22
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [ACR Stealer (Amatera Stealer) Uses ClickFix Lures, WebDAV/pushd DLL Delivery, and EtherHiding to Harvest…](https://intel.threadlinqs.com/threat/TL-2026-1444) — high — 2026-07-17
- [UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant in Financially Motivated Campaign](https://intel.threadlinqs.com/threat/TL-2026-1413) — high — 2026-07-16
- [UAT-11795 (Russian) Trojanizes WebEx, Zoom, MobaXterm, DBeaver, FaceIT Installers to Deploy Starland RAT and…](https://intel.threadlinqs.com/threat/TL-2026-1411) — high — 2026-07-16
- [SpyGlace Malware Campaign by APT-C-60 (Naikon) Abuses Trusted Developer Services (GitHub, GitLab, jsDelivr…](https://intel.threadlinqs.com/threat/TL-2026-1284) — high — 2026-07-13
- [Domestic APT Spear-Phishing Campaigns (May 2026) — LNK/HTA/CHM/JSE Loaders Deploying XenoRAT, Suspected…](https://intel.threadlinqs.com/threat/TL-2026-1229) — high — 2026-07-11
- [Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…](https://intel.threadlinqs.com/threat/TL-2026-1210) — high — 2026-07-11
- [Remcos RAT: Technical Analysis of Windows Remote Access Trojan Operations](https://intel.threadlinqs.com/threat/TL-2026-1133) — high — 2026-07-05
- [Gamaredon Expands Ukraine Attacks with PteroSetup Revival and Cloud Service Abuse, Exploiting WinRAR Flaw…](https://intel.threadlinqs.com/threat/TL-2026-1216) — high — 2026-06-29
- [DeceptionAds: Fake CAPTCHA Malvertising Campaign Abusing the Monetag Ad Network to Distribute Lumma…](https://intel.threadlinqs.com/threat/TL-2026-0769) — high — 2026-06-10
- [Internet Explorer WebBrowser Control Attack Chain — Two-Click RCE via Zone/MOTW Bypass and ActiveX COM…](https://intel.threadlinqs.com/threat/TL-2026-0715) — high — 2026-06-08
- [Operation XENOFISCAL — SideCopy (Transparent Tribe / APT36 umbrella) Deploys Persistent Customized XenoRAT…](https://intel.threadlinqs.com/threat/TL-2026-0625) — high — 2026-05-29
- [Cloud Atlas APT — termsrv.dll Byte-Patch for Multi-Session RDP, PowerCloud/PowerShower/VBCloud Chain…](https://intel.threadlinqs.com/threat/TL-2026-0583) — high — 2026-05-25
- [InstallFix Campaign — Fake Claude AI Installer via Google Ads Drops mshta/ZIP-HTA Polyglot, AMSI-Bypass…](https://intel.threadlinqs.com/threat/TL-2026-0463) — high — 2026-05-05
- [EtherRAT — Node.js Backdoor with Ethereum Blockchain C2 (EtherHiding) Linked to DPRK Contagious Interview](https://intel.threadlinqs.com/threat/TL-2026-0293) — critical — 2026-03-27
- [SmartApeSG ClickFix Campaign Delivers Remcos RAT via Fake CAPTCHA Pages](https://intel.threadlinqs.com/threat/TL-2026-0225) — high — 2026-03-13

## Related CVEs

CVEs referenced by the tracked threats that use T1218.005, most frequent first.

- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2018-0802](https://intel.threadlinqs.com/cve/CVE-2018-0802)
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2020-16040](https://intel.threadlinqs.com/cve/CVE-2020-16040)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-2441](https://intel.threadlinqs.com/cve/CVE-2026-2441)

## Detection coverage

Threadlinqs maintains 101 detection rules mapped to T1218.005 (SPL 41, KQL 32, Sigma 28). Rule content is available to Blue tier accounts and above; this page shows counts only.

101 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1218 System Binary Proxy Execution](https://intel.threadlinqs.com/technique/T1218) — 170 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1218.005
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
