The open-source Koadic post-exploitation framework can abuse Windows Script Host, COM objects, and signed Windows utilities such as mshta.exe to execute payloads while minimizing its on-disk footprint. Koadic activity has been linked to APT28, and its execution patterns can begin with spearphishing before progressing through proxy execution, host discovery, UAC bypass, and collection of command output.
mshta.exe, tracked by MITRE ATT&CK as System Binary Proxy Execution: Mshta (T1218.005), is broadly abused to run malicious HTA files, scripts, DLLs, and remotely hosted payloads. Defenders can detect this behavior through process ancestry and ordered event sequences, suspicious network connections from Windows proxy binaries, Internet Explorer cache artifacts, registry modifications, and short-lived files used to redirect command output, rather than relying solely on static indicators.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
A Palo Alto Networks report associated an Outlook.exe-to-Mshta.exe process chain with APT28 activity, illustrating spearphishing-driven execution through mshta.exe.
MITRE ATT&CK documented adversary use of mshta.exe to execute malicious scripts, HTA files, DLLs, and remote payloads, including use by Koadic and numerous threat groups and malware families.
Elastic Security Labs documented EQL detections for Koadic behaviors, including Outlook-to-mshta execution, network-enabled proxy execution, Internet Explorer cache artifacts, discovery activity, UAC bypass, and short-lived redirected command-output files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.