logo

Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows

ID: 005d0f43-2604-5dc3-acdd-d1ab43028f08

STIX ID: report--005d0f43-2604-5dc3-acdd-d1ab43028f08

Feed Name: Bitdefender Labs

Threat Score
70/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Janos Gergo SZELES

...
...

Bitdefender researchers analyzed widespread abuse of the legacy Windows mshta.exe utility by multiple criminal campaigns (CountLoader, Emmenhtal Loader, LummaStealer, Amatera, ClipBanker, PurpleFox). The report describes multi-stage, often fileless infection chains leveraging obfuscated HTA and PowerShell code, social-engineering lures (fake installers, clipboard hijack “human verification” pages), detailed IoCs (domains, URLs, IPs, SHA256s), observed infrastructure shifts (TLD patterns), and recommended user and technical mitigations to reduce exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.