HideUL is a Windows defense-evasion utility used to suppress or conceal the mouse cursor during attacker-controlled interactive sessions. It has been executed through unauthorized ScreenConnect remote-management sessions following phishing-led compromise, reducing visible evidence of hands-on-keyboard activity on affected endpoints. No threat-actor attribution or additional functionality is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named tool executed during the second incident for defense evasion.
A defense-evasion binary executed through the unauthorized ScreenConnect session during the second incident.
A defense-evasion binary used to suppress or hide the cursor and reduce visible evidence of interactive remote activity.
Purpose-built defense-evasion utility executed interactively through ScreenConnect. The content does not describe its precise evasion mechanism beyond dropping a temporary file.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.