Mshta is Microsoft HTML Application Host (mshta.exe), the runtime used to execute HTML Applications (.hta) and embedded scripts.
Mshta is a tool tracked across 16 threat clusters and 29 intelligence report mentions on ThreatCluster. First observed November 6, 2025; most recent activity July 20, 2026.
Mshta is Microsoft HTML Application Host (mshta.exe), the runtime used to execute HTML Applications (.hta) and embedded scripts. Attackers abuse HTA/mshta to run malicious code and deliver payloads, with illicit HTA files now used to distribute KimJongRAT, making this a notable threat vector in Windows environments.
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
On May 14, 2026, the SmartApeSG threat actor launched a supply chain attack by injecting malicious JavaScript into the Okendo Reviews widget, which is used by over 18,000 brands. This compromise allowed the delivery of…
Kaspersky has uncovered a targeted Horabot campaign primarily affecting victims in Mexico, with 93% of the 5,384 recorded victims located there. The attack employs a fake CAPTCHA page that instructs users to execute a…
Cybercriminals are increasingly using legitimate system tools like PowerShell and WMI to deploy malware, creating stealthy threats that evade traditional defenses. The ANY.RUN Q1 2026 Cyber Risk report highlights a…
The InstallFix campaign targets users by creating fake installation pages for Anthropic's Claude AI, tricking them into executing malware. This sophisticated social engineering tactic exploits the growing reliance on AI…
An exposed server functioning as a malware delivery lab was discovered following an MDR alert. The lab contained over 1,000 artifacts, showcasing how attackers are leveraging generative AI for rapid lure generation and…
Bitdefender researchers have identified that the Microsoft HTML Application Host (MSHTA) utility is being actively exploited by cybercriminals to deliver a variety of malware, including infostealers and loaders. Despite…
On July 2, 2026, Opera introduced a new security feature called Paste Protect to prevent clipboard hijacking and code injection attacks, specifically targeting ClickFix-style attacks. These attacks trick users into…
APT36, also known as Transparent Tribe, conducted a spear-phishing campaign targeting Indian government, strategic, and academic organizations. The campaign involved delivering malicious LNK files disguised as PDFs,…
The ClickFix malware has evolved to utilize videos, countdown timers, and OS detection to trick users into self-infecting their devices. Cybercriminals employ social engineering techniques to manipulate victims into…
Mshta is Microsoft HTML Application Host (mshta.exe), the runtime used to execute HTML Applications (.hta) and embedded scripts.
The most recent intelligence report mentioning Mshta on ThreatCluster is dated July 20, 2026. Activity was first observed November 6, 2025, giving a tracked span from then to July 20, 2026.
Across ThreatCluster reporting, Mshta most frequently co-occurs with Apt36, Kimsuky, Stealth Falcon, Transparent Tribe, Unc3569, among 12 tracked related entities.
The most significant recent cluster is “Iranian APT Groups Target Israeli Organizations with Modular C2 Frameworks” (10 articles · Updated July 6, 2026). Mshta appears across 16 threat clusters in total, listed above with sources.
Mshta appears in 29 intelligence report mentions across 16 deduplicated threat clusters, aggregated from 17,000+ monitored sources.