UACMe is an open-source Windows privilege-escalation toolset focused on bypassing User Account Control (UAC) across multiple Windows versions. It is widely used as a proof-of-concept and operational utility to launch follow-on payloads with elevated privileges after initial compromise. The project implements numerous UAC bypass methods, including abuse of auto-elevated components, COM interfaces, registry hijacks, scheduled-task abuse, DLL hijacking, and other Windows-specific elevation paths, making it a flexible post-exploitation aid rather than a standalone intrusion platform.
The tool has been observed in real-world intrusions as a privilege-escalation component used by multiple threat actors and malware operators. Reported use includes ransomware affiliates, espionage campaigns, and North Korean-linked operations such as Lazarus- and Kimsuky-associated activity, where it was employed after phishing- or watering-hole-based compromise to obtain administrative execution for additional malware deployment, persistence, credential access, and remote-control tooling. It has also been referenced in campaigns that paired it with droppers, downloaders, backdoors, and remote administration malware.
UACMe targets Microsoft Windows systems and is best characterized as a post-compromise privilege-escalation utility. Its primary value to operators is defense evasion and privilege escalation by suppressing or bypassing standard elevation prompts, enabling subsequent payloads to run with higher integrity without requiring normal user approval flows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UAC Bypass 도구는 이전 사례들과 동일하게 최신 사례에서도 지속적으로 사용되고 있다. 과거 사례들과의 차이점이라면 UACMe를 기반으로 제작한 형태 외에도 또 다른 오픈 소스 PoC를 사용하였다는 점이다.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Framework: MITRE ATT&CK Tactic: Name: Privilege Escalation Id: TA0004 ... Technique: Name: Abuse Elevation Control Mechanism Id: T1548 ... Sub Technique: Name: Bypass User Account Control Id: T1548.002
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Privilege-escalation/UAC bypass tooling used in the campaign to elevate execution on victim systems.
Privilege escalation/UAC bypass tooling used as part of the intrusion chain.
Open-source Windows UAC bypass/privilege escalation toolkit; referenced here as a module (akagi.exe) used within the broader infection chain to bypass UAC.
Privilege-escalation malware/tool used post-infection to elevate privileges on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.