HTA — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
January 26, 2026
Last Seen
July 16, 2026

HTA is a technology platform tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed January 26, 2026; most recent activity July 16, 2026.

Related Threat Clusters

  • Russian UAT-11795 Targets Users with Trojans in Legitimate Software

    A Russian threat actor known as UAT-11795 has been deploying the Starland RAT and WLDR agent since June 2025, primarily targeting users in the U.S., Germany, Romania, and Venezuela. The group uses trojanized installers…

    6 articles · Updated July 17, 2026
  • XWorm RAT Exploits CVE-2018-0802 in Phishing Campaign

    A multi-stage phishing campaign has been detected distributing the XWorm remote access trojan (RAT) via malicious Excel attachments. The attack leverages CVE-2018-0802 in Microsoft Equation Editor to execute a fileless…

    1 article · Updated February 12, 2026
  • PeckBirdy Framework Targets Gambling Industries in China

    PeckBirdy is a JScript-based command-and-control framework utilized by China-aligned APT groups to exploit LOLBins. Since 2023, it has been deployed against gambling industries and Asian government entities, delivering…

    7 articles · Updated January 27, 2026

Recent Intelligence Reports

  • Russian hackers trojanize WebEx, Zoom apps to push Starland malware — Bleepingcomputer · July 16, 2026
  • XWorm Phish Abuses CVE-2018-0802 for Fileless RAT — Socprime · February 11, 2026
  • PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China — Feeds.Trendmicro · January 26, 2026

CVSS v3.1 Breakdown