Multiple reports describe abuse of the Microsoft-signed fodhelper.exe binary to bypass Windows User Account Control on Windows 10 by hijacking the per-user registry path HKCU\Software\Classes\ms-settings\Shell\Open\command. In the documented technique, an attacker sets a malicious default command and an empty DelegateExecute value so that fodhelper.exe, which auto-elevates, launches attacker-controlled code with high integrity. Public proof-of-concept examples showed the method spawning elevated cmd.exe or PowerShell sessions, and noted that the bypass generally requires the user to already belong to the local Administrators group.
The same technique was later observed in a phishing campaign analyzed by SANS, where a malicious Word document used embedded OLE objects instead of macros to trigger a batch file on victim systems. That script checked for Windows 10, attempted UAC bypass via fodhelper.exe and eventvwr.exe, then downloaded additional payloads from attacker-controlled infrastructure including 23.98.155.192 and hpsj.firewall-gateway.net. The infection chain ultimately deployed the Octopus backdoor, which used HTTP-based command and control with AES-encrypted communications and supported victim reporting, file download, PowerShell reset, and arbitrary command execution.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
cocomelonc published a C/C++ proof of concept showing how to create HKCU\Software\Classes\ms-settings\Shell\Open\command, set an empty DelegateExecute value, and launch fodhelper.exe to obtain an elevated cmd.exe session. The post also noted that Glupteba malware has used the technique for privilege escalation.
SANS ISC analyzed a malicious Word document used in a targeted phishing campaign that relied on embedded OLE batch files instead of macros. The batch script checked for Windows 10, attempted UAC bypass via fodhelper.exe and eventvwr.exe, then downloaded additional payloads that led to an Octopus backdoor.
PentestLab documented the fodhelper.exe UAC bypass and published a PowerShell proof of concept that creates the ms-settings registry keys, launches fodhelper.exe, and removes the keys afterward. The post also noted Bash Bunny and Metasploit implementations of the same technique.
The fodhelper.exe UAC bypass technique was discovered by winscripting. The method abuses per-user registry keys under HKCU\Software\Classes\ms-settings\shell\open\command so fodhelper.exe runs attacker-controlled commands with high integrity on Windows 10.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
cocomelonc.github.io
Open sourceisc.sans.edu
Open sourcepentestlab.blog
Open sourcewinscripting.blog
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.