Mshta - Tool

Threat entity extracted from intelligence sources

Frequency
29
occurrences
First Seen
November 6, 2025
Last Seen
July 20, 2026

Mshta is Microsoft HTML Application Host (mshta.exe), the runtime used to execute HTML Applications (.hta) and embedded scripts.

Mshta is a tool tracked across 16 threat clusters and 29 intelligence report mentions on ThreatCluster. First observed November 6, 2025; most recent activity July 20, 2026.

Overview

Mshta is Microsoft HTML Application Host (mshta.exe), the runtime used to execute HTML Applications (.hta) and embedded scripts. Attackers abuse HTA/mshta to run malicious code and deliver payloads, with illicit HTA files now used to distribute KimJongRAT, making this a notable threat vector in Windows environments.

Related Threat Clusters

  • Iranian APT Groups Target Israeli Organizations with Modular C2 Frameworks

    In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…

    10 articles · Updated July 6, 2026
  • SmartApeSG Targets Okendo Reviews Widget in Supply Chain Attack

    On May 14, 2026, the SmartApeSG threat actor launched a supply chain attack by injecting malicious JavaScript into the Okendo Reviews widget, which is used by over 18,000 brands. This compromise allowed the delivery of…

    4 articles · Updated June 19, 2026
  • New Horabot Campaign Targets Victims in Mexico with Banking Trojan

    Kaspersky has uncovered a targeted Horabot campaign primarily affecting victims in Mexico, with 93% of the 5,384 recorded victims located there. The attack employs a fake CAPTCHA page that instructs users to execute a…

    2 articles · Updated March 18, 2026
  • Cybercriminals Exploit Trusted Tools for Malware Deployment

    Cybercriminals are increasingly using legitimate system tools like PowerShell and WMI to deploy malware, creating stealthy threats that evade traditional defenses. The ANY.RUN Q1 2026 Cyber Risk report highlights a…

    4 articles · Updated June 5, 2026
  • InstallFix Campaign Exploits AI Trust to Deliver Malware via Fake Install Pages

    The InstallFix campaign targets users by creating fake installation pages for Anthropic's Claude AI, tricking them into executing malware. This sophisticated social engineering tactic exploits the growing reliance on AI…

    53 articles · Updated May 5, 2026
  • Exposed Malware Delivery Lab Reveals AI-Driven Phishing Operations

    An exposed server functioning as a malware delivery lab was discovered following an MDR alert. The lab contained over 1,000 artifacts, showcasing how attackers are leveraging generative AI for rapid lure generation and…

    2 articles · Updated July 20, 2026
  • MSHTA Utility Exploited in Ongoing Malware Campaigns

    Bitdefender researchers have identified that the Microsoft HTML Application Host (MSHTA) utility is being actively exploited by cybercriminals to deliver a variety of malware, including infostealers and loaders. Despite…

    8 articles · Updated May 19, 2026
  • Opera Launches Paste Protect to Combat ClickFix Attacks

    On July 2, 2026, Opera introduced a new security feature called Paste Protect to prevent clipboard hijacking and code injection attacks, specifically targeting ClickFix-style attacks. These attacks trick users into…

    14 articles · Updated July 2, 2026
  • APT36 Campaign Uses LNK Files for Cyberespionage Against Indian Targets

    APT36, also known as Transparent Tribe, conducted a spear-phishing campaign targeting Indian government, strategic, and academic organizations. The campaign involved delivering malicious LNK files disguised as PDFs,…

    2 articles · Updated January 5, 2026
  • ClickFix Malware Campaign Enhances Deception Tactics

    The ClickFix malware has evolved to utilize videos, countdown timers, and OS detection to trick users into self-infecting their devices. Cybercriminals employ social engineering techniques to manipulate victims into…

    2 articles · Updated November 7, 2025

Recent Intelligence Reports

  • Inside an Exposed Malware Delivery Lab: OPSEC Failures Behind a WebDAV Phishing Operation — Rapid7 · July 20, 2026
  • Inside an Exposed Malware Delivery Lab: OPSEC Failures Behind a WebDAV Phishing Operation — Rapid7 · July 20, 2026
  • MITRE ATT&CK - MuddyWater — attack.mitre.org · July 8, 2026
  • Seraph Secure — www.seraphsecure.com · July 2, 2026
  • Opera's new security feature stops copy paste attacks from malicious websites — Engadget · July 2, 2026
  • Smartapesg Returns With Unique Obfuscation Techniques — www.blumira.com · June 18, 2026
  • Hackers Weaponize Trusted Tools to Deploy Notorious Malware — Gbhackers · June 5, 2026
  • Hackers Weaponize Trusted Tools to Deploy Notorious Malware — Gbhackers · June 5, 2026

Frequently asked questions

What is Mshta?

Mshta is Microsoft HTML Application Host (mshta.exe), the runtime used to execute HTML Applications (.hta) and embedded scripts.

Is Mshta still active?

The most recent intelligence report mentioning Mshta on ThreatCluster is dated July 20, 2026. Activity was first observed November 6, 2025, giving a tracked span from then to July 20, 2026.

What is Mshta associated with?

Across ThreatCluster reporting, Mshta most frequently co-occurs with Apt36, Kimsuky, Stealth Falcon, Transparent Tribe, Unc3569, among 12 tracked related entities.

What are the latest developments involving Mshta?

The most significant recent cluster is “Iranian APT Groups Target Israeli Organizations with Modular C2 Frameworks” (10 articles · Updated July 6, 2026). Mshta appears across 16 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on Mshta?

Mshta appears in 29 intelligence report mentions across 16 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown