{
  "id": 7074108,
  "title": "Phishing operation exploits Windows Mshta for credential theft",
  "url": "https://urgent.news/2026/09/13/phishing-operation-exploits-windows-mshta-for-credential-theft-7074108",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-13T06:16:26.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/phishing-operation-exploits-windows-mshta-for-credential-theft/"
  },
  "original_language": "en",
  "account": "A phishing campaign targeting Spanish-speaking users of global organizations began in June, utilizing Microsoft's legitimate mshta.exe utility to distribute malicious HTML Application files. Security researchers, Fortra Intelligence and Research Experts (FIRE), discovered the ongoing operation primarily employs Spanish-language lures such as invoice and judicial-notice emails to deceive recipients. The phishing messages, originating from Italian free-email service libero.it or Microsoft 365 infrastructure, guide victims through URL-shortening services to a page that downloads an HTA file. Upon opening the file, Windows invokes mshta.exe, a trusted Windows binary capable of executing HTA files, JavaScript, and VBScript. The malicious HTA loads remote JavaScript, causing the activity to appear hidden from the user. The second stage of the attack gathers system information using Windows Management Instrumentation, PowerShell, and environment variables to determine subsequent payload deployment. The JavaScript stage then constructs a Base64-encoded ZIP archive through HTML smuggling, which contains a 7-Zip self-extracting executable disguised as a Firefox installer. Upon execution, the payload extracts and launches the next stage from a temporary directory, with the goal of stealing local secrets. The campaign employs various evasion tactics, including random file names, off-screen HTA execution, embedded Base64 content, and polymorphic executables, making static hash-based blocking ineffective. FIRE advises defenders to monitor mshta.exe running from user-writable locations, restrict its usage, and examine mail-flow rules for suspicious activity.",
  "summary": "A phishing campaign active since June is abusing Microsoft’s legitimate mshta. exe utility to run malicious HTML Application files, profile infected Windows systems and deliver follow-on malware capable of stealing credentials and other local secrets, security researchers have found. Fortra Intelligence and Research Experts, known as FIRE, said the operation remains active and is primarily…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "Arabian Post",
        "title": "Phishing operation exploits Windows Mshta for credential theft",
        "url": "https://urgent.news/2026/09/13/phishing-operation-exploits-windows-mshta-for-credential-theft",
        "published": "2026-09-13T06:16:26.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}