Hackers Abuse MSHTA in Fileless Attacks Targeting Crypto Assets and Wallets
MSHTA is a built-in Microsoft Windows program dating from the Internet Explorer era that can execute HTML Applications. Hackers use it to evade conventional antivirus detection and launch malware in memory, targeting crypto users’ login credentials, private keys and wallet assets. The attacks are increasing risks to transaction security.
Cybersecurity companies recently found that attackers were using fake software and ClickFix social-engineering tactics to trick victims into running MSHTA commands. The attackers then deployed information-stealing malware such as LummaStealer and could also replace wallet addresses during transfers. Related reports did not identify specific victim organizations or disclose losses, the exact discovery date or the number of victims.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →