Urgent.News

What's breaking now, across thousands of outlets.

Tech

Phishing operation exploits Windows Mshta for credential theft

A phishing campaign active since June is abusing Microsoft’s legitimate mshta. exe utility to run malicious HTML Application files, profile infected Windows systems and deliver follow-on malware capable of stealing credentials and other local secrets, security researchers have found. Fortra Intelligence and Research Experts, known as FIRE, said the operation remains active and is primarily…

A phishing operation, active since June, has been exploiting Microsoft's legitimate mshta.exe utility to carry out credential theft and deliver malware, according to security researchers. The campaign primarily targets Spanish-speaking users at global organizations. The attackers use Spanish-language lures, such as fake invoices and judicial notices, to trick recipients into following malicious links.

The attack begins with phishing messages from Italian free-email service libero.it or Microsoft 365 infrastructure. Victims are directed through URL-shortening services to download an HTA file, which is executed by the Windows mshta.exe utility. This allows the malware to run hidden and load remote JavaScript, avoiding user detection.

The second stage gathers system information using Windows Management Instrumentation, PowerShell, and environment variables. The malicious JavaScript then decodes a Base64-encoded ZIP archive through HTML smuggling, distributing a 7-Zip self-extracting executable disguised as a Firefox installer. Once executed, it extracts and launches the final payload from a temporary directory.

The campaign's primary objective is to steal local secrets through an information stealer, although it can support other payloads. To complicate detection, the attackers use random file names, off-screen HTA execution, embedded Base64 content, and polymorphic executables with varying hashes. The campaign is notable for its consistent Spanish-language elements in emails, social-engineering text, and source code.

Experts recommend monitoring mshta.exe command lines referencing suspicious content and restricting its use when not necessary. Disabling or restricting mshta.exe can help prevent exploitation of this vulnerability.

Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at thearabianpost.com →

More in Tech

OpenCompany เปิดซอร์ส 22 บริษัทให้ agent รัน แต่สมองยังอยู่ที่อื่น

OpenCompany เปิดซอร์ส 22 บริษัทให้ agent รัน แต่สมองยังอยู่ที่อื่น โดย Nokka (นก-กา) | 13 กันยายน 2026 บทความนี้เขียนโดย AI (deepseek-v4.1-flash) ผ่าน Hermes Agent ตรวจสอบและเรียบเรียงโดย Nokka…

More from Sunday 13 September →