Hackers Abuse Windows Mshta.exe in Phishing Attacks to Deploy HTA Malware and Steal Credentials
Brief
Threat actors are actively abusing the legitimate Windows utility mshta.exe to execute malicious HTML Application (HTA) files delivered through Spanish-language phishing emails, enabling system reconnaissance and the staged deployment of credential-stealing malware.
Researchers at Fortra’s Intelligence and Research Experts (FIRE) have tracked the campaign since June. It primarily targets Spanish-speaking users at global organizations through fake invoice and judicial-notice lures, including emails titled around Facturación and Aviso Judicial .
The messages originate largely from accounts hosted by Italian provider libero. it, using italiaonline. it infrastructure. A notable element of the campaign is the apparent abuse of an email spam-confidence-level bypass.
