Hackers Abuse MSHTA in Fileless Attacks Targeting Crypto Assets and Wallets
MSHTA is a built-in Microsoft Windows program dating from the Internet Explorer era that can execute HTML Applications. Hackers use it to evade conventional antivirus detection and launch malware in memory, targeting crypto users’ login credentials, private keys and wallet assets. The attacks are increasing risks to transaction security.
Cybersecurity companies recently found that attackers were using fake software and ClickFix social-engineering tactics to trick victims into running MSHTA commands. The attackers then deployed information-stealing malware such as LummaStealer and could also replace wallet addresses during transfers. Related reports did not identify specific victim organizations or disclose losses, the exact discovery date or the number of victims.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.