logo

Hackers Abuse MSHTA Legacy Windows Tool to Deliver LummaStealer and Amatera Malware

ID: f65872ec-cc09-5ccd-b3e8-c20b1e0e816c

STIX ID: report--f65872ec-cc09-5ccd-b3e8-c20b1e0e816c

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Tushar Subhra Dutta

...
...

The report from Bitdefender/CSN describes multiple active campaigns abusing the legacy Windows MSHTA utility to fetch and execute remote scripts that lead to credential- and wallet-stealing malware (LummaStealer, Amatera) and other loaders (CountLoader, Emmenhtal, ClipBanker, PurpleFox); campaigns use phishing, fake installers, clipboard-based social engineering (ClickFix), fileless in-memory execution, and a large set of domains/IPs/hashes as IoCs while recommending blocking or restricting mshta.exe, user education, and layered defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.