1200KM / simulation
T1218.001 Compiled HTML File — Attack Simulation
Adversaries may abuse Compiled HTML files (.chm) to conceal malicious code. CHM files are commonly distributed as part of the Microsoft HTML Help system. CHM files are compressed compilations of various content such as HTML documents, images, and scripting/web related programming languages such VBA, JScript, Java, and ActiveX. CHM content is displayed using underlying components of the Internet Explorer browser loaded by the HTML Help executable…
Technique description
Adversaries may abuse Compiled HTML files (.chm) to conceal malicious code. CHM files are commonly distributed as part of the Microsoft HTML Help system. CHM files are compressed compilations of various content such as HTML documents, images, and scripting/web related programming languages such VBA, JScript, Java, and ActiveX. CHM content is displayed using underlying components of the Internet Explorer browser loaded by the HTML Help executable…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Compiled HTML Help Remote Payload
Procedure 0f8af516-9818-4172-922b-42986ef1e81d; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Invoke CHM Shortcut Command with ITS and Help Topic
Procedure 15756147-7470-4a83-87fb-bb5662526247; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Decompile Local CHM File
Procedure 20cb05e0-1fa5-406d-92c1-84da4ba01813; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Invoke CHM with default Shortcut Command Execution
Procedure 29d6f0d7-be63-4482-8827-ea77126c1ef7; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Invoke CHM with Script Engine and Help Topic
Procedure 4f83adda-f5ec-406d-b318-9773c9ca92e5; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Compiled HTML Help Local Payload
Procedure 5cb87818-0d7c-4469-b7ef-9224107aebe8; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Invoke CHM Simulate Double click
Procedure 5decef42-92b8-4a93-9eb2-877ddcb9401a; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Invoke CHM with InfoTech Storage Protocol Handler
Procedure b4094750-5fc7-4e8e-af12-b4e36bf5e7f6; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.