UACMe is an open-source Windows proof-of-concept toolkit and collection of techniques for bypassing User Account Control (UAC) across multiple Windows versions. It contains numerous numbered methods that abuse Windows auto-elevation behavior, COM interfaces, registry associations, scheduled tasks, DLL-loading behavior, and other privilege-boundary weaknesses or design characteristics to execute a payload with elevated integrity without the normal UAC consent flow. It is commonly used as a post-compromise privilege-escalation utility rather than as a standalone malware family. UACMe has been observed in operations associated with Kimsuky, Lazarus-linked Operation Bookcodes, Patchwork, and LockBit affiliates, among other threat activity. It targets Microsoft Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UAC Bypass 도구는 이전 사례들과 동일하게 최신 사례에서도 지속적으로 사용되고 있다. 과거 사례들과의 차이점이라면 UACMe를 기반으로 제작한 형태 외에도 또 다른 오픈 소스 PoC를 사용하였다는 점이다.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Outil de contournement de l’UAC utilisé par AvisLoader, via sa méthode 41, afin d’obtenir une élévation de privilèges.
Privilege-escalation/UAC bypass tooling used in the campaign to elevate execution on victim systems.
Privilege escalation/UAC bypass tooling used as part of the intrusion chain.
Open-source Windows UAC bypass/privilege escalation toolkit; referenced here as a module (akagi.exe) used within the broader infection chain to bypass UAC.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.