logo

New FileFix attack runs JScript while bypassing Windows MoTW alerts

ID: c57beec9-c004-5404-aa8d-24577ca2026a

STIX ID: report--c57beec9-c004-5404-aa8d-24577ca2026a

Feed Name: Bleeping Computer

Threat Score
50/100

Date Published: 2025-07-01

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A new FileFix attack variant abuses browser behavior when saving pages as "Webpage, Complete" (MIME type text/html) so the saved file lacks the Mark of the Web; if a user is tricked into renaming that file to .HTA, mshta.exe will immediately execute embedded JScript without Windows warnings. The report explains the attack flow, social engineering baits (for example persuading users to save MFA backup codes), and suggests mitigations including disabling/removing mshta.exe, enabling file extension visibility, and blocking HTML attachments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.