MSHTA Abuse Resurfaces as Threat Actors Push LummaStealer and Amatera Payloads
ID: 1d731ac9-63cc-58c6-bf27-0960d2daeb5b
STIX ID: report--1d731ac9-63cc-58c6-bf27-0960d2daeb5b
Feed Name: Cyber Press
Threat Score
This report describes active campaigns abusing the Windows mshta.exe binary as a LOLBIN to deliver information-stealers (LummaStealer, Amatera) via HTA/Python-based loaders and ClickFix social engineering, employing fileless PowerShell execution and AMSI bypass; it includes actionable IOCs (SHA256 hashes and URLs) and mitigation guidance (restrict mshta.exe/wscript.exe, user training, layered defenses).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
