Bitdefender warned that attackers are increasingly abusing Microsoft’s legacy mshta.exe utility as a living-off-the-land tool to execute remote or in-memory scripts and deliver malware including LummaStealer, Amatera, CountLoader, Emmenhtal Loader, ClipBanker, and PurpleFox. The campaigns rely on phishing, fake software downloads, SEO poisoning, cracked-software lures, fake social media posts, Discord messages, and ClickFix-style fake CAPTCHA or reCAPTCHA prompts that trick users into launching malicious commands. Researchers said much of the observed mshta.exe traffic was tied to typosquatted or attacker-controlled domains masquerading as legitimate services, with payloads focused on credential theft, session cookie theft, cryptocurrency wallet theft, and persistent compromise.
One highlighted infection chain used a fake Setup.exe containing a bundled Python interpreter and a renamed MSHTA binary to retrieve additional payloads, while other chains used fileless execution through PowerShell, WScript, HTA content, and even msiexec to fetch disguised installer packages. Bitdefender said legitimate enterprise use of MSHTA is declining while malicious use is rising, and noted that although VBScript was deprecated in 2024 and is expected to be disabled by default in 2027, Microsoft has not indicated plans to remove MSHTA. The company urged defenders to disable or restrict mshta.exe and wscript.exe where possible, migrate away from legacy scripts, improve user awareness, and rely on layered behavioral and runtime defenses.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Bitdefender recommended that organizations disable or restrict mshta.exe and wscript.exe where possible, migrate away from legacy scripts, improve user awareness, and use layered behavioral and runtime defenses. The guidance accompanied its reporting on the renewed abuse of MSHTA in modern malware campaigns.
Researchers linked Emmenhtal Loader and LummaStealer delivery to fake CAPTCHA, fake reCAPTCHA, and human-verification pages that trick victims into pasting malicious commands. Those commands launched MSHTA filelessly in memory and led to infostealer infections.
Bitdefender described a CountLoader infection chain in which a fake Setup.exe, actually a bundled Python interpreter with a renamed MSHTA binary, retrieved payloads from attacker-controlled domains masquerading as trusted services. The infrastructure reportedly shifted from .cc domains to .vg and .gl domains over time.
Bitdefender reported a sharp increase in malicious MSHTA detections and said most observed MSHTA-related traffic was tied to typosquatted or attacker-controlled infrastructure rather than benign enterprise use. The researchers said the increase had been visible since the start of 2026 as legitimate administrative use continued to decline.
Bitdefender documented ongoing abuse of the legacy Windows utility mshta.exe in delivery chains for LummaStealer, Amatera, CountLoader, Emmenhtal Loader, ClipBanker, and PurpleFox. The campaigns used HTA scripts, PowerShell, WScript, msiexec, phishing, fake software downloads, cracked software lures, Discord phishing, and ClickFix-style prompts to execute malware.
Microsoft deprecated VBScript in the second half of 2024 and announced plans to disable it by default in 2027 and remove it from Windows entirely. Bitdefender noted there was no public indication that MSHTA would be removed alongside it.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 175 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.