Palo Alto Networks Advanced WildFire now supports inline prevention for CMD, CHM, and CAB file-based malware

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Community Blogs
6 min read
Community Team Member

Strata Graphics (1).jpg

This blog was written by Pradeep Pokhariyal, Principal Product Manager

 

Introduction

 

Threat actors have fundamentally refined their tradecraft. Rather than relying on easily flagged artifacts like raw executables or macro-enabled Office files, modern adversaries increasingly weaponize native Windows utilities and built-in administrative formats. Tools like CMD batch scripts, Compiled HTML Help (.chm) files, and Cabinet (.cab) archives are trusted system components by design—a trait that makes them ideal mechanisms for stealthy initial access and execution.

 

To counter this evolving tactic, Palo Alto Networks Advanced WildFire now provides comprehensive sandboxing and dynamic behavioral analysis for CMD, CHM, and CAB file types. By expanding deep detonation capabilities across these high-risk vectors, Advanced WildFire ensures robust protection against sophisticated targeted campaigns while strengthening defenses against critical efficacy benchmark scenarios.

 

Key Capabilities at a Glance

 

  • Script & Shell Execution Analysis (.cmd / .bat): Inspects heavily obfuscated command-line scripts, nested execution chains, and hidden PowerShell invocations executed via the native command prompt.

 

  • HTML Help File Parsing (.chm): Unpacks embedded HTML/JScript content and monitors for unauthorized process spawning (such as hh.exe dropping malicious payloads).

 

  • Archive & Cabinet Inspection (.cab): Recursively extracts, scans, and behaviorally detonates nested binaries or scripts packaged within administrative compression archives.

 

The Attacker's Logic for choosing CMD, CHM and CAB

 

The principle driving the abuse of these formats is straightforward: blend in. When a Windows system executes cmd.exe, invokes the HTML Help executable (hh.exe), or extracts a .cab archive via native utilities like expand.exe, these represent routine system behaviors. Security products trained solely to flag anomalous file extensions face a fundamental challenge—the file format itself is not the anomaly; the behavioral chain hidden inside it is.

 

This aligns with MITRE ATT&CK T1218 (System Binary Proxy Execution) and T1059 (Command and Scripting Interpreter): adversaries leverage trusted, signed Windows utilities and native interpreters to proxy execution and evade detection, effectively inheriting the legitimacy of the host process.

 

CMD Files

 

Batch scripts (.cmd, .bat) represent the oldest scripting primitive in the Windows ecosystem. While defenders have long focused heavily on monitoring PowerShell and WScript as high-risk interpreters, CMD-based stagers often benefit from lower relative scrutiny. Modern CMD-based malware chains together heavy obfuscation, dynamic environment variable manipulation, and Living-off-the-Land Binaries (LOLBins) like certutil or bitsadmin to stage second-stage payloads—all while appearing as routine administrative activity.

 

CHM Files

 

Compiled HTML Help files (.chm) package HTML, JavaScript, and ActiveX components into a single binary container. Opening a CHM file causes the native Windows HTML Help executable (hh.exe) to render the content and any embedded scripts. Threat actors leverage the built-in HHCtrl ActiveX control (hhctrl.ocx) to invoke mshta.exe, which in turn executes remote HTML Application (.hta) files. These HTA files carry VBScript or PowerShell payloads capable of downloading and executing final-stage malware in memory, leaving minimal artifacts on disk.

 

Threat groups like TA558 have operationalized this technique at scale:

 

User opens .chm → hh.exe renders content → HHCtrl ActiveX calls mshta.exe → mshta.exe fetches remote .hta from Google Firebase → VBScript/PowerShell downloads AsyncRAT or RevengeRAT

 

What makes this chain particularly dangerous is its reliance on signed, Microsoft-trusted binaries at every intermediate step. No unsigned executable touches the disk until the final payload is delivered.

 

CAB Files

 

Cabinet archives function simultaneously as a delivery mechanism and an evasion layer. Threat actors use .cab files to containerize stagers, payloads, or configuration data, taking advantage of legacy security products that inspect archives only at the header level rather than fully uncompressing and behaviorally detonating the contents. Furthermore, because CAB files are routinely used in legitimate Windows Update and software deployment workflows, they easily blend into the ambient telemetry defenders must filter through.

 

Notable Recent Campaigns

 

Mustang Panda — PlugX via CHM (March 2026)

 

The China-nexus APT group Mustang Panda executed a campaign using a deceptively simple delivery chain:

  1. A ZIP archive was delivered to the target.
  2. Inside the archive: a single LNK shortcut file.
  3. The LNK file, when executed, contacted a remote server and downloaded a CHM file.
  4. The CHM file executed the PlugX backdoor—a persistent remote access tool associated with Chinese espionage operations for over a decade.

The use of a CHM file as the terminal payload delivery stage—rather than as a first-stage dropper—reflects a maturation in how threat actors think about CHM abuse. The format is not just a lure; it is a capable execution environment.

 

TA558 — AsyncRAT and RevengeRAT Distribution

 

TA558, a financially motivated threat actor with a long history of targeting the hospitality and travel sectors in Latin America, has expanded its toolset to include CHM-based distribution of commodity RATs. Their infrastructure leveraged Google Firebase for payload hosting, using the reputation of a major cloud provider to bypass URL filtering and categorization-based controls.

These campaigns demonstrated that CHM abuse is not limited to nation-state actors. The technique is accessible, effective, and increasingly common across the threat landscape.

 

What This Means for Palo Alto Network Customers

 

Existing Deployments — No Configuration Required

 

Advanced WildFire automatically applies the new file type support to all traffic passing through enabled inspection points. Please ensure that you have file forwarding enabled for CMD, CHM, and CAB detonation.

 

Verdicts Feed the Broader Platform

 

Verdicts from Advanced WildFire propagate in real time to all PAN products and solutions — ensuring that a malicious CHM file detonated for one customer becomes a blocked indicator for all customers globally within minutes.

Telemetry for Threat Hunting

Security teams using Cortex XDR can pivot on Advanced WildFire verdicts for these new file types to investigate whether any CHM, CMD, or CAB files with malicious verdicts were seen in their environment — and correlate against endpoint telemetry to assess whether execution occurred before the file was identified.

 

Conclusion

 

The expansion of Advanced WildFire coverage to CMD, CHM, and CAB files is not an incremental update — it is a direct response to how the threat landscape has evolved. Sophisticated threat actors, from Mustang Panda to TA558, have demonstrated that these file formats are reliable, effective, and underdetected attack vectors. They choose them precisely because many security controls treat them as low-risk or fail to detonate them entirely.

Advanced WildFire now closes that gap. Every CHM that attempts to proxy execution through hh.exe, every CMD script that stages a payload through certutil, every CAB archive that conceals a first-stage implant — these detonate in an instrumented environment, get classified, and become intelligence that protects the entire Palo Alto Networks customer base.

 

Attackers hide in plain sight. Advanced WildFire looks closer.

 

For technical documentation on Advanced WildFire file type coverage and supported analysis environments, visit the Palo Alto Networks documentation portal. To evaluate Advanced WildFire in your environment, contact your Palo Alto Networks account team.

  • 489 Views
  • 0 comments
  • 1 Likes
Labels
Contributors
Top Liked Authors