- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
This blog was written by Pradeep Pokhariyal, Principal Product Manager
Threat actors have fundamentally refined their tradecraft. Rather than relying on easily flagged artifacts like raw executables or macro-enabled Office files, modern adversaries increasingly weaponize native Windows utilities and built-in administrative formats. Tools like CMD batch scripts, Compiled HTML Help (.chm) files, and Cabinet (.cab) archives are trusted system components by design—a trait that makes them ideal mechanisms for stealthy initial access and execution.
To counter this evolving tactic, Palo Alto Networks Advanced WildFire now provides comprehensive sandboxing and dynamic behavioral analysis for CMD, CHM, and CAB file types. By expanding deep detonation capabilities across these high-risk vectors, Advanced WildFire ensures robust protection against sophisticated targeted campaigns while strengthening defenses against critical efficacy benchmark scenarios.
The principle driving the abuse of these formats is straightforward: blend in. When a Windows system executes cmd.exe, invokes the HTML Help executable (hh.exe), or extracts a .cab archive via native utilities like expand.exe, these represent routine system behaviors. Security products trained solely to flag anomalous file extensions face a fundamental challenge—the file format itself is not the anomaly; the behavioral chain hidden inside it is.
This aligns with MITRE ATT&CK T1218 (System Binary Proxy Execution) and T1059 (Command and Scripting Interpreter): adversaries leverage trusted, signed Windows utilities and native interpreters to proxy execution and evade detection, effectively inheriting the legitimacy of the host process.
CMD Files
Batch scripts (.cmd, .bat) represent the oldest scripting primitive in the Windows ecosystem. While defenders have long focused heavily on monitoring PowerShell and WScript as high-risk interpreters, CMD-based stagers often benefit from lower relative scrutiny. Modern CMD-based malware chains together heavy obfuscation, dynamic environment variable manipulation, and Living-off-the-Land Binaries (LOLBins) like certutil or bitsadmin to stage second-stage payloads—all while appearing as routine administrative activity.
CHM Files
Compiled HTML Help files (.chm) package HTML, JavaScript, and ActiveX components into a single binary container. Opening a CHM file causes the native Windows HTML Help executable (hh.exe) to render the content and any embedded scripts. Threat actors leverage the built-in HHCtrl ActiveX control (hhctrl.ocx) to invoke mshta.exe, which in turn executes remote HTML Application (.hta) files. These HTA files carry VBScript or PowerShell payloads capable of downloading and executing final-stage malware in memory, leaving minimal artifacts on disk.
Threat groups like TA558 have operationalized this technique at scale:
User opens .chm → hh.exe renders content → HHCtrl ActiveX calls mshta.exe → mshta.exe fetches remote .hta from Google Firebase → VBScript/PowerShell downloads AsyncRAT or RevengeRAT
What makes this chain particularly dangerous is its reliance on signed, Microsoft-trusted binaries at every intermediate step. No unsigned executable touches the disk until the final payload is delivered.
CAB Files
Cabinet archives function simultaneously as a delivery mechanism and an evasion layer. Threat actors use .cab files to containerize stagers, payloads, or configuration data, taking advantage of legacy security products that inspect archives only at the header level rather than fully uncompressing and behaviorally detonating the contents. Furthermore, because CAB files are routinely used in legitimate Windows Update and software deployment workflows, they easily blend into the ambient telemetry defenders must filter through.
Mustang Panda — PlugX via CHM (March 2026)
The China-nexus APT group Mustang Panda executed a campaign using a deceptively simple delivery chain:
The use of a CHM file as the terminal payload delivery stage—rather than as a first-stage dropper—reflects a maturation in how threat actors think about CHM abuse. The format is not just a lure; it is a capable execution environment.
TA558 — AsyncRAT and RevengeRAT Distribution
TA558, a financially motivated threat actor with a long history of targeting the hospitality and travel sectors in Latin America, has expanded its toolset to include CHM-based distribution of commodity RATs. Their infrastructure leveraged Google Firebase for payload hosting, using the reputation of a major cloud provider to bypass URL filtering and categorization-based controls.
These campaigns demonstrated that CHM abuse is not limited to nation-state actors. The technique is accessible, effective, and increasingly common across the threat landscape.
Existing Deployments — No Configuration Required
Advanced WildFire automatically applies the new file type support to all traffic passing through enabled inspection points. Please ensure that you have file forwarding enabled for CMD, CHM, and CAB detonation.
Verdicts Feed the Broader Platform
Verdicts from Advanced WildFire propagate in real time to all PAN products and solutions — ensuring that a malicious CHM file detonated for one customer becomes a blocked indicator for all customers globally within minutes.
Telemetry for Threat Hunting
Security teams using Cortex XDR can pivot on Advanced WildFire verdicts for these new file types to investigate whether any CHM, CMD, or CAB files with malicious verdicts were seen in their environment — and correlate against endpoint telemetry to assess whether execution occurred before the file was identified.
The expansion of Advanced WildFire coverage to CMD, CHM, and CAB files is not an incremental update — it is a direct response to how the threat landscape has evolved. Sophisticated threat actors, from Mustang Panda to TA558, have demonstrated that these file formats are reliable, effective, and underdetected attack vectors. They choose them precisely because many security controls treat them as low-risk or fail to detonate them entirely.
Advanced WildFire now closes that gap. Every CHM that attempts to proxy execution through hh.exe, every CMD script that stages a payload through certutil, every CAB archive that conceals a first-stage implant — these detonate in an instrumented environment, get classified, and become intelligence that protects the entire Palo Alto Networks customer base.
Attackers hide in plain sight. Advanced WildFire looks closer.
For technical documentation on Advanced WildFire file type coverage and supported analysis environments, visit the Palo Alto Networks documentation portal. To evaluate Advanced WildFire in your environment, contact your Palo Alto Networks account team.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| Subject | Likes |
|---|---|
| 2 Likes | |
| 1 Like | |
| 1 Like | |
| 1 Like | |
| 1 Like |

