Bitdefender Details Malware Campaigns Abusing Windows’ MSHTA Utility

Summary
Bitdefender researchers analyzed campaigns using Windows’ built-in MSHTA utility to deliver stealers, loaders and other malware through multi-stage script chains, often aided by social engineering.
Key points
- Bitdefender observed increased MSHTA activity, with the legacy Windows utility used to retrieve and execute remote scripts as part of malware delivery chains.
- Campaigns used MSHTA to deliver LummaStealer, Amatera, CountLoader, Emmenhtal Loader, ClipBanker and PurpleFox.
- Attackers used lures including cracked software downloads and ClickFix-style fake verification pages that trick users into running commands.
- Observed chains combined HTA scripts with PowerShell, in-memory execution, obfuscation and, in some cases, persistence or security-tool evasion.
- CountLoader infrastructure shifted from domains using .cc to newer .vg and .gl domains; Bitdefender also identified associated indicators of compromise.
- The researchers recommend user awareness, layered security controls and restricting or blocking mshta.exe and wscript.exe where they are not needed.
Article Details
- Attack Vectors
- Messages, social media posts, and SEO-poisoned websites lure users into downloading archives advertised as free or cracked software. In the analyzed CountLoader chain, a legitimate Python interpreter named Setup.exe loads a malicious script from a bundled Lib directory, which launches a renamed MSHTA executable to retrieve an HTA loader.
- Discord phishing messages link to fake human-verification pages that copy a malicious command to the clipboard and instruct users to paste it into the Windows Run dialog. MSHTA then retrieves an Emmenhtal Loader HTA.
- MSHTA retrieves and executes remote HTA content in the ClipBanker chain, which proceeds through PowerShell scripts that establish persistence, add Windows Defender exclusions, and deliver further payloads.
- PurpleFox delivery uses an MSHTA command to launch msiexec, which downloads and executes an MSI package disguised as a .png file.
- Other observed chains use MSHTA to launch PowerShell commands that download scripts, decode concealed URLs, or execute payloads in memory.
- Defensive Notes
- Educate users about untrusted software downloads, fake verification instructions, clipboard-based command lures, and the risks of executing commands they do not understand.
- Where legitimate workflows do not require them, restrict or block mshta.exe and wscript.exe and migrate older scripts to modern alternatives.
- Use layered controls across script execution, command-line abuse, in-memory stages, and payload delivery, including pre-execution detection and runtime behavioral blocking.
- Do not treat every MSHTA execution as malicious: the article also observed apparently legitimate, though unorthodox, DriverPack update activity.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | acio-patron[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | alpha-centavr[.]cc | CountLoader/LummaStealer infrastructure contacted by the renamed MSHTA executable. |
| DOMAIN | alphazero1-endscape[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | azure-s3-bucket[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | bigbrainsholdings[.]com | CountLoader/LummaStealer infrastructure. |
| DOMAIN | ccleaner[.]gl | New CountLoader infrastructure. |
| DOMAIN | communicationfirewall-security[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | critical-service[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | debank-api[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | deluxe[.]gl | New CountLoader infrastructure. |
| DOMAIN | domain-monitoring[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | explorer[.]vg | New CountLoader infrastructure. |
| DOMAIN | fileless-market[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | fileless-storage-s3[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | files-storage[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | forest-entity[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | geo-foundation[.]vg | New CountLoader infrastructure. |
| DOMAIN | globalsnn1-new[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | globalsnn2-new[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | globalsnn3-new[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | google-services[.]cc | CountLoader/LummaStealer infrastructure imitating a legitimate service. |
| DOMAIN | hardware-office[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | health-smooth-eu2[.]com | CountLoader/LummaStealer infrastructure. |
| DOMAIN | health-smooth-eu3[.]com | CountLoader/LummaStealer infrastructure. |
| DOMAIN | hell1-kitty[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | hell10-kitty[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | hell2-kitty[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | hell3-kitty[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | hell4-kitty[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | hell5-kitty[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | hell6-kitty[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | hell7-kitty[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | hell8-kitty[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | hell9-kitty[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | holiday-forever[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | holiday-updateservice[.]com | CountLoader/LummaStealer infrastructure. |
| DOMAIN | holypriest[.]gl | New CountLoader infrastructure. |
| DOMAIN | hosting-control[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | humancheck[.]shop | Suspicious host of a fake human-verification page used in the Emmenhtal infection chain. |
| DOMAIN | immortal-service[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | indeanapolice[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | memory-protection-layer1[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | memory-scanner[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | microservice-update-s1-bucket[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | microservice-update-s2-bucket[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | microservice[.]gl | New CountLoader infrastructure. |
| DOMAIN | ms-team-ping6[.]com | CountLoader/LummaStealer infrastructure. |
| DOMAIN | msedge[.]vg | New CountLoader infrastructure. |
| DOMAIN | msgrouppolicy[.]vg | New CountLoader infrastructure. |
| DOMAIN | my-smart-house1[.]com | CountLoader/LummaStealer infrastructure. |
| DOMAIN | network-defender[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | offshore-storage[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | parent-control[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | polystore9-servicebucket[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | py-installer[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | s1-microservice-updatehub[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | s10-microservice-updatehub[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | s2-microservice-updatehub[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | s3-microservice-updatehub[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | s3-updatehub[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | s4-microservice-updatehub[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | s5-microservice-updatehub[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | s6-microservice-updatehub[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | s7-microservice-updatehub[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | s8-microservice-updatehub[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | s9-microservice-updatehub[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | sentinel1-endpoint-security[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | silverhost[.]vg | New CountLoader infrastructure. |
| DOMAIN | some-othertag[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | system-monitor[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | urugvai[.]cc | CountLoader/LummaStealer infrastructure. |
| DOMAIN | web3-walletnotify[.]cc | CountLoader/LummaStealer infrastructure. |
| IPV4 | 100[.]1[.]121[.]27 | PurpleFox MSI location. |
| IPV4 | 103[.]113[.]195[.]244 | PurpleFox MSI location. |
| IPV4 | 103[.]115[.]17[.]90 | PurpleFox MSI location. |
| IPV4 | 103[.]124[.]106[.]194 | Address in an MSHTA command's list of PurpleFox MSI download locations. |
| IPV4 | 103[.]36[.]223[.]87 | PurpleFox MSI location. |
| IPV4 | 103[.]55[.]70[.]212 | PurpleFox MSI location. |
| IPV4 | 103[.]83[.]212[.]194 | PurpleFox MSI location. |
| IPV4 | 107[.]175[.]187[.]11 | PurpleFox MSI location. |
| IPV4 | 110[.]42[.]51[.]229 | PurpleFox MSI location. |
| IPV4 | 110[.]45[.]196[.]155 | PurpleFox MSI location. |
| IPV4 | 122[.]165[.]219[.]142 | PurpleFox MSI location. |
| IPV4 | 156[.]224[.]232[.]98 | PurpleFox MSI location. |
| IPV4 | 157[.]66[.]153[.]154 | PurpleFox MSI location. |
| IPV4 | 173[.]208[.]166[.]226 | PurpleFox MSI location. |
| IPV4 | 185[.]156[.]172[.]22 | Host of the password-gated PHP script used to deliver the Lalala stealer script. |
| IPV4 | 185[.]208[.]159[.]199 | IP hosting the ClipBanker-chain checking.ps1 script. |
| IPV4 | 187[.]102[.]48[.]229 | PurpleFox MSI location. |
| IPV4 | 190[.]111[.]12[.]242 | PurpleFox MSI location. |
| IPV4 | 193[.]112[.]70[.]226 | PurpleFox MSI location. |
| IPV4 | 195[.]189[.]28[.]244 | Address in an MSHTA command's list of PurpleFox MSI download locations. |
| IPV4 | 201[.]138[.]238[.]195 | PurpleFox MSI location. |
| IPV4 | 204[.]44[.]110[.]216 | PurpleFox MSI location. |
| IPV4 | 222[.]73[.]29[.]92 | PurpleFox MSI location. |
| IPV4 | 58[.]221[.]252[.]210 | PurpleFox MSI location. |
| IPV4 | 58[.]221[.]59[.]20 | Address in an MSHTA command's list of PurpleFox MSI download locations. |
| IPV4 | 60[.]173[.]116[.]152 | PurpleFox MSI location. |
| IPV4 | 61[.]136[.]101[.]152 | PurpleFox MSI location. |
| IPV4 | 61[.]147[.]108[.]92 | PurpleFox MSI location. |
| IPV4 | 87[.]96[.]21[.]84 | IP hosting further ClipBanker-chain payloads. |
| IPV4 | 89[.]117[.]2[.]159 | PurpleFox MSI location. |
| SHA256 | 02630fa994b1566ad1515fd87220fc037b967f07495985a3637d68d7e08c57ee | Obfuscated PowerShell artifact in the Emmenhtal chain. |
| SHA256 | 1e0e375f3ee82d5af5dfe6f7df0e2fac9a7d37c67add3390d05a93afd85b7c84 | LummaStealer payload executed in the analyzed Emmenhtal chain. |
| SHA256 | 333e2192f2551415659fb4094e81b911708921bb588eecf65e27f51c9938dfc2 | ClipBanker-chain checking.ps1 script. |
| SHA256 | 38fe562136ade372fc4cedde67826aeea8404e93a54a4a4736ddb4c8c8d4c96d | ClipBanker-chain ichigo-lite.ps1 downloader. |
| SHA256 | 7d0487afc91b0fe8b2fbf732ab54c3c07e86bf69471bba6c283aabea190499ba | ClipBanker-chain del.ps1 cleanup script. |
| SHA256 | aa845a8fb4ab38aebe6a16a2a8f80ca4467ac0991d3eef4d8a10bdf97dedb1e9 | Initial HTA launched after the Emmenhtal ClickFix lure. |
| URL | hxxp[:]//92[.]255[.]57[.]155/b[.]jpg | Image-disguised PowerShell script location in a chain associated with XWorm/Danabot. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe analyzed chains conceal scripts and URLs with character assembly, Base64 encoding, encrypted payloads, garbage data, and split PowerShell keywords.T1036.005 · Match Legitimate Resource Name or LocationThe CountLoader archive presents a legitimate Python interpreter as Setup.exe and a renamed MSHTA executable as iso2022.exe.T1053.005 · Scheduled TaskThe ClipBanker chain establishes persistence through scheduled tasks with service-like names.T1059.001 · PowerShellMSHTA-launched commands execute PowerShell downloaders, in-memory scripts, and follow-on payloads.T1059.005 · Visual BasicMalicious HTA content and MSHTA command lines execute VBScript to create WScript.Shell objects and launch commands.T1059.007 · JavaScriptEmmenhtal HTA content uses JavaScript to decode and execute an embedded script.T1105 · Ingress Tool TransferMSHTA, PowerShell, and msiexec retrieve remote HTA content, scripts, or an MSI package for execution.T1218.005 · MshtaMultiple malware chains use the signed Windows mshta.exe utility to retrieve and execute malicious HTA or script content.T1562.001 · Disable or Modify ToolsThe ClipBanker chain adds Windows Defender exclusions, while an Emmenhtal-stage PowerShell script patches clr.dll to bypass AMSI.T1620 · Reflective Code LoadingAn Emmenhtal-stage PowerShell script decodes a Base64 byte array, loads it as an assembly, and invokes its entry point in memory.
People
Malware
AmateraAt the lower end, MSHTA is heavily used in delivery chains for commodity stealers such as LummaStealer and Amatera, as well as loaders such as CountLoader and Emmenhtal Loader.CastleLoader“ClickFix” attacks were also used with a new LummaStealer and CastleLoader campaign, not to mention the malware used to infect the devices of people who downloaded pirated versions of Leonardo DiCaprio’s new film, OneClipBankerAt the same time, it also shows up in more advanced and persistent malware campaigns, including ClipBanker and PurpleFox. This range of abuse highlights why MSHTA continues to matter to defenders: it’s not a singleCountLoaderAt the lower end, MSHTA is heavily used in delivery chains for commodity stealers such as LummaStealer and Amatera, as well as loaders such as CountLoader and Emmenhtal Loader.Danabotcontain a PowerShell script downloaded and executed in memory. These IPs are typically used by XWorm/Danabot. PowerShell keywords are split into multiple tokens to bypass detection.Emmenhtal LoaderAt the lower end, MSHTA is heavily used in delivery chains for commodity stealers such as LummaStealer and Amatera, as well as loaders such as CountLoader and Emmenhtal Loader.LalalaThe next category involves the Lalala information stealer, where the script is delivered only if the POST request to the PHP script includes a predefined password. Other PowerShell keywords remain unobfuscated.LummaStealer“ClickFix” attacks were also used with a new LummaStealer and CastleLoader campaign, not to mention the malware used to infect the devices of people who downloaded pirated versions of Leonardo DiCaprio’s new film, OnePurpleFoxsame time, it also shows up in more advanced and persistent malware campaigns, including ClipBanker and PurpleFox. This range of abuse highlights why MSHTA continues to matter to defenders: it’s not a single malwareXWormactually contain a PowerShell script downloaded and executed in memory. These IPs are typically used by XWorm/Danabot. PowerShell keywords are split into multiple tokens to bypass detection.
Vendors
BitdefenderBitdefender security researchers have discovered that attackers continue to exploit Microsoft HTML Application Host (MSHTA), a legacy utility available by default on Windows systems that can execute VBScript andMicrosoftMicrosoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows
Products
Bitdefender Threat Intelligence SolutionsAdditionally, Bitdefender Threat Intelligence Solutions help organizations detect, investigate, and respond to cyber threats faster by providing real-time intelligence on malicious files, URLs, domains, and IPs.Bitdefender Ultimate Securitycan reduce exposure by ensuring that they run a comprehensive security solution, such as Bitdefender Ultimate Security.DriverPackDriverPack - an example of legitimate usageInternet ExplorerIn recent months, we noticed an increase in detections of mshta.exe in the execution chain, indicating that it remains a relevant Living-off-the-Land binary even after standalone Internet Explorer was retired.Microsoft DefenderThe role of this script is to ensure Windows Defender exclusions and persistence, which executes the ClipBanker downloader obtained from: hxxp[://]87[.]96[.]21[.]84/ichigo-lite[.]ps1Microsoft EdgeAlthough Internet Explorer reached end of support on June 15, 2022, Microsoft Edge still includes an IE mode to ensure backward compatibility, with support promised at least until 2029 [2].Microsoft WindowsMicrosoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows
Tools
AutorunsThis script cleans up the files used during the attack and terminates processes that might have been involved in dynamic analysis in a sandbox (e.g., Procmon, Autoruns).ProcmonThis script cleans up the files used during the attack and terminates processes that might have been involved in dynamic analysis in a sandbox (e.g., Procmon, Autoruns).VirusTotalThese domains are often labeled as LummaStealer infrastructure on VirusTotal because Lumma is often the final payload delivered through this chain, and the same domains often appear in Lumma-related configurations.