Mark RadarMARK RADAR
EN
Event File CRYPTO Phishing

Hackers Abuse MSHTA in Fileless Attacks Targeting Crypto Assets and Wallets

1 reports · First detected 2026-05-22 · Last active 2026-05-22

MSHTA is a built-in Microsoft Windows program dating from the Internet Explorer era that can execute HTML Applications. Hackers use it to evade conventional antivirus detection and launch malware in memory, targeting crypto users’ login credentials, private keys and wallet assets. The attacks are increasing risks to transaction security.

Cybersecurity companies recently found that attackers were using fake software and ClickFix social-engineering tactics to trick victims into running MSHTA commands. The attackers then deployed information-stealing malware such as LummaStealer and could also replace wallet addresses during transfers. Related reports did not identify specific victim organizations or disclose losses, the exact discovery date or the number of victims.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR