logo

MSHTA Abuse Resurfaces as Threat Actors Push LummaStealer and Amatera Payloads

ID: 1d731ac9-63cc-58c6-bf27-0960d2daeb5b

STIX ID: report--1d731ac9-63cc-58c6-bf27-0960d2daeb5b

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Varshini

...
...

This report describes active campaigns abusing the Windows mshta.exe binary as a LOLBIN to deliver information-stealers (LummaStealer, Amatera) via HTA/Python-based loaders and ClickFix social engineering, employing fileless PowerShell execution and AMSI bypass; it includes actionable IOCs (SHA256 hashes and URLs) and mitigation guidance (restrict mshta.exe/wscript.exe, user training, layered defenses).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.