T1218.001 - Compiled HTML File - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
March 3, 2026
Last Seen
August 21, 2026

Related Threat Clusters

  • JanaWare Ransomware Targets Turkey Using Adwind RAT

    The JanaWare ransomware campaign has emerged, targeting users in Turkey through a customized variant of the Adwind RAT. The malware is distributed via phishing emails containing malicious JAR files, which, when…

    9 articles · Updated April 15, 2026
  • Abuse of Microsoft Defender Driver Enables Kernel-Level Attacks

    Research reveals that the Microsoft Defender Boot-Time Removal driver (BTR.sys) can be weaponized to perform unauthorized file and registry operations from kernel mode. This exploitation does not rely on traditional…

    10 articles · Updated August 20, 2026
  • Signed Malware Deploys RMM Backdoors via Phishing Campaigns

    Microsoft's Defender Security Research Team reported phishing campaigns utilizing signed malware disguised as workplace applications. This malware, backed by a stolen EV certificate, installs remote monitoring and…

    5 articles · Updated March 5, 2026

Recent Intelligence Reports

  • Windows Defender Driver Abuse Enables Kernel — Gbhackers · August 21, 2026
  • JanaWare Ransomware Targets Turkey via Adwind RAT — Socprime · April 15, 2026
  • Signed malware impersonating workplace apps deploys RMM backdoors — Blogs.Microsoft · March 3, 2026

CVSS v3.1 Breakdown