logo

Malicious HTA's not just for Spammers

ID: d482299f-9faf-5828-9d99-d17dec19e40b

STIX ID: report--d482299f-9faf-5828-9d99-d17dec19e40b

Feed Name: TrustedSec blog

Threat Score
50/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This report explains how attackers use malicious HTML Application (HTA) files—launched by mshta.exe—to execute PowerShell payloads in-memory, describes example scripts and tooling (Unicorn, Metasploit/msfvenom, Out-HTA), and offers operational tips for increasing success (naming, hosting over HTTPS, browser redirects). It is an instructional overview of HTA-based droppers and web-delivery techniques rather than a specific incident or observed campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.