Bitdefender Details Malware Campaigns Abusing Windows’ MSHTA Utility

· Original article ↗

Summary

Bitdefender researchers analyzed campaigns using Windows’ built-in MSHTA utility to deliver stealers, loaders and other malware through multi-stage script chains, often aided by social engineering.

Key points

  • Bitdefender observed increased MSHTA activity, with the legacy Windows utility used to retrieve and execute remote scripts as part of malware delivery chains.
  • Campaigns used MSHTA to deliver LummaStealer, Amatera, CountLoader, Emmenhtal Loader, ClipBanker and PurpleFox.
  • Attackers used lures including cracked software downloads and ClickFix-style fake verification pages that trick users into running commands.
  • Observed chains combined HTA scripts with PowerShell, in-memory execution, obfuscation and, in some cases, persistence or security-tool evasion.
  • CountLoader infrastructure shifted from domains using .cc to newer .vg and .gl domains; Bitdefender also identified associated indicators of compromise.
  • The researchers recommend user awareness, layered security controls and restricting or blocking mshta.exe and wscript.exe where they are not needed.

Article Details

Attack Vectors
  • Messages, social media posts, and SEO-poisoned websites lure users into downloading archives advertised as free or cracked software. In the analyzed CountLoader chain, a legitimate Python interpreter named Setup.exe loads a malicious script from a bundled Lib directory, which launches a renamed MSHTA executable to retrieve an HTA loader.
  • Discord phishing messages link to fake human-verification pages that copy a malicious command to the clipboard and instruct users to paste it into the Windows Run dialog. MSHTA then retrieves an Emmenhtal Loader HTA.
  • MSHTA retrieves and executes remote HTA content in the ClipBanker chain, which proceeds through PowerShell scripts that establish persistence, add Windows Defender exclusions, and deliver further payloads.
  • PurpleFox delivery uses an MSHTA command to launch msiexec, which downloads and executes an MSI package disguised as a .png file.
  • Other observed chains use MSHTA to launch PowerShell commands that download scripts, decode concealed URLs, or execute payloads in memory.
Defensive Notes
  • Educate users about untrusted software downloads, fake verification instructions, clipboard-based command lures, and the risks of executing commands they do not understand.
  • Where legitimate workflows do not require them, restrict or block mshta.exe and wscript.exe and migrate older scripts to modern alternatives.
  • Use layered controls across script execution, command-line abuse, in-memory stages, and payload delivery, including pre-execution detection and runtime behavioral blocking.
  • Do not treat every MSHTA execution as malicious: the article also observed apparently legitimate, though unorthodox, DriverPack update activity.

Indicators of compromise

TypeIndicatorContext
DOMAINacio-patron[.]ccCountLoader/LummaStealer infrastructure.
DOMAINalpha-centavr[.]ccCountLoader/LummaStealer infrastructure contacted by the renamed MSHTA executable.
DOMAINalphazero1-endscape[.]ccCountLoader/LummaStealer infrastructure.
DOMAINazure-s3-bucket[.]ccCountLoader/LummaStealer infrastructure.
DOMAINbigbrainsholdings[.]comCountLoader/LummaStealer infrastructure.
DOMAINccleaner[.]glNew CountLoader infrastructure.
DOMAINcommunicationfirewall-security[.]ccCountLoader/LummaStealer infrastructure.
DOMAINcritical-service[.]ccCountLoader/LummaStealer infrastructure.
DOMAINdebank-api[.]ccCountLoader/LummaStealer infrastructure.
DOMAINdeluxe[.]glNew CountLoader infrastructure.
DOMAINdomain-monitoring[.]ccCountLoader/LummaStealer infrastructure.
DOMAINexplorer[.]vgNew CountLoader infrastructure.
DOMAINfileless-market[.]ccCountLoader/LummaStealer infrastructure.
DOMAINfileless-storage-s3[.]ccCountLoader/LummaStealer infrastructure.
DOMAINfiles-storage[.]ccCountLoader/LummaStealer infrastructure.
DOMAINforest-entity[.]ccCountLoader/LummaStealer infrastructure.
DOMAINgeo-foundation[.]vgNew CountLoader infrastructure.
DOMAINglobalsnn1-new[.]ccCountLoader/LummaStealer infrastructure.
DOMAINglobalsnn2-new[.]ccCountLoader/LummaStealer infrastructure.
DOMAINglobalsnn3-new[.]ccCountLoader/LummaStealer infrastructure.
DOMAINgoogle-services[.]ccCountLoader/LummaStealer infrastructure imitating a legitimate service.
DOMAINhardware-office[.]ccCountLoader/LummaStealer infrastructure.
DOMAINhealth-smooth-eu2[.]comCountLoader/LummaStealer infrastructure.
DOMAINhealth-smooth-eu3[.]comCountLoader/LummaStealer infrastructure.
DOMAINhell1-kitty[.]ccCountLoader/LummaStealer infrastructure.
DOMAINhell10-kitty[.]ccCountLoader/LummaStealer infrastructure.
DOMAINhell2-kitty[.]ccCountLoader/LummaStealer infrastructure.
DOMAINhell3-kitty[.]ccCountLoader/LummaStealer infrastructure.
DOMAINhell4-kitty[.]ccCountLoader/LummaStealer infrastructure.
DOMAINhell5-kitty[.]ccCountLoader/LummaStealer infrastructure.
DOMAINhell6-kitty[.]ccCountLoader/LummaStealer infrastructure.
DOMAINhell7-kitty[.]ccCountLoader/LummaStealer infrastructure.
DOMAINhell8-kitty[.]ccCountLoader/LummaStealer infrastructure.
DOMAINhell9-kitty[.]ccCountLoader/LummaStealer infrastructure.
DOMAINholiday-forever[.]ccCountLoader/LummaStealer infrastructure.
DOMAINholiday-updateservice[.]comCountLoader/LummaStealer infrastructure.
DOMAINholypriest[.]glNew CountLoader infrastructure.
DOMAINhosting-control[.]ccCountLoader/LummaStealer infrastructure.
DOMAINhumancheck[.]shopSuspicious host of a fake human-verification page used in the Emmenhtal infection chain.
DOMAINimmortal-service[.]ccCountLoader/LummaStealer infrastructure.
DOMAINindeanapolice[.]ccCountLoader/LummaStealer infrastructure.
DOMAINmemory-protection-layer1[.]ccCountLoader/LummaStealer infrastructure.
DOMAINmemory-scanner[.]ccCountLoader/LummaStealer infrastructure.
DOMAINmicroservice-update-s1-bucket[.]ccCountLoader/LummaStealer infrastructure.
DOMAINmicroservice-update-s2-bucket[.]ccCountLoader/LummaStealer infrastructure.
DOMAINmicroservice[.]glNew CountLoader infrastructure.
DOMAINms-team-ping6[.]comCountLoader/LummaStealer infrastructure.
DOMAINmsedge[.]vgNew CountLoader infrastructure.
DOMAINmsgrouppolicy[.]vgNew CountLoader infrastructure.
DOMAINmy-smart-house1[.]comCountLoader/LummaStealer infrastructure.
DOMAINnetwork-defender[.]ccCountLoader/LummaStealer infrastructure.
DOMAINoffshore-storage[.]ccCountLoader/LummaStealer infrastructure.
DOMAINparent-control[.]ccCountLoader/LummaStealer infrastructure.
DOMAINpolystore9-servicebucket[.]ccCountLoader/LummaStealer infrastructure.
DOMAINpy-installer[.]ccCountLoader/LummaStealer infrastructure.
DOMAINs1-microservice-updatehub[.]ccCountLoader/LummaStealer infrastructure.
DOMAINs10-microservice-updatehub[.]ccCountLoader/LummaStealer infrastructure.
DOMAINs2-microservice-updatehub[.]ccCountLoader/LummaStealer infrastructure.
DOMAINs3-microservice-updatehub[.]ccCountLoader/LummaStealer infrastructure.
DOMAINs3-updatehub[.]ccCountLoader/LummaStealer infrastructure.
DOMAINs4-microservice-updatehub[.]ccCountLoader/LummaStealer infrastructure.
DOMAINs5-microservice-updatehub[.]ccCountLoader/LummaStealer infrastructure.
DOMAINs6-microservice-updatehub[.]ccCountLoader/LummaStealer infrastructure.
DOMAINs7-microservice-updatehub[.]ccCountLoader/LummaStealer infrastructure.
DOMAINs8-microservice-updatehub[.]ccCountLoader/LummaStealer infrastructure.
DOMAINs9-microservice-updatehub[.]ccCountLoader/LummaStealer infrastructure.
DOMAINsentinel1-endpoint-security[.]ccCountLoader/LummaStealer infrastructure.
DOMAINsilverhost[.]vgNew CountLoader infrastructure.
DOMAINsome-othertag[.]ccCountLoader/LummaStealer infrastructure.
DOMAINsystem-monitor[.]ccCountLoader/LummaStealer infrastructure.
DOMAINurugvai[.]ccCountLoader/LummaStealer infrastructure.
DOMAINweb3-walletnotify[.]ccCountLoader/LummaStealer infrastructure.
IPV4100[.]1[.]121[.]27PurpleFox MSI location.
IPV4103[.]113[.]195[.]244PurpleFox MSI location.
IPV4103[.]115[.]17[.]90PurpleFox MSI location.
IPV4103[.]124[.]106[.]194Address in an MSHTA command's list of PurpleFox MSI download locations.
IPV4103[.]36[.]223[.]87PurpleFox MSI location.
IPV4103[.]55[.]70[.]212PurpleFox MSI location.
IPV4103[.]83[.]212[.]194PurpleFox MSI location.
IPV4107[.]175[.]187[.]11PurpleFox MSI location.
IPV4110[.]42[.]51[.]229PurpleFox MSI location.
IPV4110[.]45[.]196[.]155PurpleFox MSI location.
IPV4122[.]165[.]219[.]142PurpleFox MSI location.
IPV4156[.]224[.]232[.]98PurpleFox MSI location.
IPV4157[.]66[.]153[.]154PurpleFox MSI location.
IPV4173[.]208[.]166[.]226PurpleFox MSI location.
IPV4185[.]156[.]172[.]22Host of the password-gated PHP script used to deliver the Lalala stealer script.
IPV4185[.]208[.]159[.]199IP hosting the ClipBanker-chain checking.ps1 script.
IPV4187[.]102[.]48[.]229PurpleFox MSI location.
IPV4190[.]111[.]12[.]242PurpleFox MSI location.
IPV4193[.]112[.]70[.]226PurpleFox MSI location.
IPV4195[.]189[.]28[.]244Address in an MSHTA command's list of PurpleFox MSI download locations.
IPV4201[.]138[.]238[.]195PurpleFox MSI location.
IPV4204[.]44[.]110[.]216PurpleFox MSI location.
IPV4222[.]73[.]29[.]92PurpleFox MSI location.
IPV458[.]221[.]252[.]210PurpleFox MSI location.
IPV458[.]221[.]59[.]20Address in an MSHTA command's list of PurpleFox MSI download locations.
IPV460[.]173[.]116[.]152PurpleFox MSI location.
IPV461[.]136[.]101[.]152PurpleFox MSI location.
IPV461[.]147[.]108[.]92PurpleFox MSI location.
IPV487[.]96[.]21[.]84IP hosting further ClipBanker-chain payloads.
IPV489[.]117[.]2[.]159PurpleFox MSI location.
SHA25602630fa994b1566ad1515fd87220fc037b967f07495985a3637d68d7e08c57eeObfuscated PowerShell artifact in the Emmenhtal chain.
SHA2561e0e375f3ee82d5af5dfe6f7df0e2fac9a7d37c67add3390d05a93afd85b7c84LummaStealer payload executed in the analyzed Emmenhtal chain.
SHA256333e2192f2551415659fb4094e81b911708921bb588eecf65e27f51c9938dfc2ClipBanker-chain checking.ps1 script.
SHA25638fe562136ade372fc4cedde67826aeea8404e93a54a4a4736ddb4c8c8d4c96dClipBanker-chain ichigo-lite.ps1 downloader.
SHA2567d0487afc91b0fe8b2fbf732ab54c3c07e86bf69471bba6c283aabea190499baClipBanker-chain del.ps1 cleanup script.
SHA256aa845a8fb4ab38aebe6a16a2a8f80ca4467ac0991d3eef4d8a10bdf97dedb1e9Initial HTA launched after the Emmenhtal ClickFix lure.
URLhxxp[:]//92[.]255[.]57[.]155/b[.]jpgImage-disguised PowerShell script location in a chain associated with XWorm/Danabot.

MITRE ATT&CK

People

Malware

AmateraAt the lower end, MSHTA is heavily used in delivery chains for commodity stealers such as LummaStealer and Amatera, as well as loaders such as CountLoader and Emmenhtal Loader.CastleLoader“ClickFix” attacks were also used with a new LummaStealer and CastleLoader campaign, not to mention the malware used to infect the devices of people who downloaded pirated versions of Leonardo DiCaprio’s new film, OneClipBankerAt the same time, it also shows up in more advanced and persistent malware campaigns, including ClipBanker and PurpleFox. This range of abuse highlights why MSHTA continues to matter to defenders: it’s not a singleCountLoaderAt the lower end, MSHTA is heavily used in delivery chains for commodity stealers such as LummaStealer and Amatera, as well as loaders such as CountLoader and Emmenhtal Loader.Danabotcontain a PowerShell script downloaded and executed in memory. These IPs are typically used by XWorm/Danabot. PowerShell keywords are split into multiple tokens to bypass detection.Emmenhtal LoaderAt the lower end, MSHTA is heavily used in delivery chains for commodity stealers such as LummaStealer and Amatera, as well as loaders such as CountLoader and Emmenhtal Loader.LalalaThe next category involves the Lalala information stealer, where the script is delivered only if the POST request to the PHP script includes a predefined password. Other PowerShell keywords remain unobfuscated.LummaStealer“ClickFix” attacks were also used with a new LummaStealer and CastleLoader campaign, not to mention the malware used to infect the devices of people who downloaded pirated versions of Leonardo DiCaprio’s new film, OnePurpleFoxsame time, it also shows up in more advanced and persistent malware campaigns, including ClipBanker and PurpleFox. This range of abuse highlights why MSHTA continues to matter to defenders: it’s not a single malwareXWormactually contain a PowerShell script downloaded and executed in memory. These IPs are typically used by XWorm/Danabot. PowerShell keywords are split into multiple tokens to bypass detection.

Vendors

Products

Tools

Related Articles