logo

Microsoft’s Retired IE Tool MSHTA Now Being Used in Fileless Malware Attacks

ID: d65f4c4c-2263-5f15-a90d-6034661e632b

STIX ID: report--d65f4c4c-2263-5f15-a90d-6034661e632b

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Deeba Ahmed

...
...

Bitdefender research shows threat actors are actively abusing the legacy Windows mshta.exe binary to run fileless VBScript/JavaScript and deploy multiple malware families — including loaders (CountLoader, Emmenhtal) and infostealers (LummaStealer, Amatera) — via social engineering (fake ads, pirated downloads, Discord phishing) and disguised payloads. The report lists specific IOCs (domains, IPs, filenames), notes some benign uses (DriverPack updates), and recommends restricting/blocking mshta.exe and wscript.exe until VBScript is retired.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.