Feeds.Feedburner MSHTA Utility Exploited in Ongoing Malware Campaigns
Article Content
- •MSHTA is being exploited for malware delivery despite Internet Explorer's retirement.
- •Attackers use MSHTA to execute scripts via phishing and fake downloads.
- •Recent campaigns have seen a rise in the use of commodity stealers like LummaStealer.
Bitdefender researchers have identified that the Microsoft HTML Application Host (MSHTA) utility is being actively exploited by cybercriminals to deliver a variety of malware, including infostealers and loaders. Despite the retirement of Internet Explorer in 2022, MSHTA remains a default component in Windows, allowing attackers to execute scripts from local or remote files. Recent campaigns have leveraged MSHTA for distributing malware like LummaStealer and Amatera through phishing tactics, fake software downloads, and social engineering. The use of MSHTA as a Living-off-the-Land binary facilitates stealthy malware delivery, making detection challenging. Attackers have also adopted new domain patterns for their infrastructure, indicating an evolution in their tactics. The persistence of MSHTA in Windows systems highlights the risks associated with legacy tools that continue to be part of the ecosystem. Microsoft plans to fully deprecate VBScript by 2027, but MSHTA's future remains uncertain as it is still widely used in malicious activities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track Amatera in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
ClearFake WebDAV Infection Chain Targets Ukrainian Government with Amatera Stealer A cybersecurity investigation revealed a multi-stage malware operation targeting a Ukrainian government organization, utilizing a DLL named 'verification.google' executed from a WebDAV path. The attack, attributed to the threat actor UAT-10820, employs a combination of fake Google CAPTCHA prompts, Cloudflare Workers…
ClearFake Campaigns Utilize WordlistLoader to Distribute Amatera Infostealer A new malware campaign identified as ClearFake employs a loader named WordlistLoader to deploy the Amatera infostealer, targeting Windows users. This loader reconstructs shellcode from encoded English words, enhancing its evasion capabilities against detection. The Amatera infostealer has advanced features, including…