UACMe is an open-source Windows User Account Control bypass framework that aggregates numerous privilege-escalation methods across multiple Windows versions. It is primarily used as a post-compromise utility to launch follow-on payloads with elevated privileges by abusing auto-elevated components, COM interfaces, scheduled tasks, DLL hijacking opportunities, and other UAC bypass primitives. Security reporting has repeatedly documented its use by both state-linked and criminal operators as an off-the-shelf privilege-escalation aid rather than as a standalone intrusion platform.
The tool has been observed in real-world operations as part of broader attack chains, including spearphishing-led intrusions attributed to Kimsuky and ransomware activity involving LockBit affiliates. In those contexts, UACMe was used after initial execution to obtain higher privileges for subsequent malware deployment, remote access enablement, credential theft, or other post-exploitation actions. Individual methods from the framework, including the ucmDccwCOM technique, have been specifically cited in incident reporting.
UACMe targets Microsoft Windows and is best characterized as offensive tooling for privilege escalation and defense evasion within an already-compromised environment. It does not inherently define a single payload family such as a backdoor or ransomware; instead, it serves as an auxiliary utility that enables elevated execution of other malware or operator-controlled components.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UAC bypass tools continue to be used in recent incidents, just as they were in previous cases. The difference from past cases is that, in addition to tools based on UACMe, another open-source PoC was also used.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Privilege escalation/UAC bypass tooling used as part of the intrusion chain.
Open-source Windows UAC bypass/privilege escalation toolkit; referenced here as a module (akagi.exe) used within the broader infection chain to bypass UAC.
Privilege-escalation malware/tool used post-infection to elevate privileges on compromised systems.
Privilege-escalation tool containing many methods to bypass Windows UAC across multiple OS versions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.