T1218.005 - Mshta - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
36
occurrences
First Seen
November 6, 2025
Last Seen
July 20, 2026

T1218.005 - Mshta is a mitre_attack tracked across 24 threat clusters and 36 intelligence report mentions on ThreatCluster. First observed November 6, 2025; most recent activity July 20, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • Inside an Exposed Malware Delivery Lab: OPSEC Failures Behind a WebDAV Phishing Operation — Rapid7 · July 20, 2026
  • Inside an Exposed Malware Delivery Lab: OPSEC Failures Behind a WebDAV Phishing Operation — Rapid7 · July 20, 2026
  • ACR Stealer exploits user interaction to steal sensitive data — Feeds.Feedburner · July 17, 2026
  • ACR Stealer Uses ClickFix, WebDAV, and Steganography to Steal Browser Credentials and Tokens — Gbhackers · July 17, 2026
  • Seraph Secure — www.seraphsecure.com · July 2, 2026
  • Smartapesg Returns With Unique Obfuscation Techniques — www.blumira.com · June 18, 2026
  • G0050 — attack.mitre.org · June 11, 2026
  • Vietnamese government — cloud.google.com · June 11, 2026

CVSS v3.1 Breakdown