New FileFix attack runs JScript while bypassing Windows MoTW alerts
ID: c57beec9-c004-5404-aa8d-24577ca2026a
STIX ID: report--c57beec9-c004-5404-aa8d-24577ca2026a
Feed Name: Bleeping Computer
A new FileFix attack variant abuses browser behavior when saving pages as "Webpage, Complete" (MIME type text/html) so the saved file lacks the Mark of the Web; if a user is tricked into renaming that file to .HTA, mshta.exe will immediately execute embedded JScript without Windows warnings. The report explains the attack flow, social engineering baits (for example persuading users to save MFA backup codes), and suggests mitigations including disabling/removing mshta.exe, enabling file extension visibility, and blocking HTML attachments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
