Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows

Imported from official source

Cybersecurity Classified by Officially

Bitdefender security researchers have discovered that attackers continue to exploit Microsoft HTML Application Host (MSHTA), a legacy utility available by default on Windows systems that can execute VBScript and JavaScript from local or remote files.

Read the original at the source: https://www.bitdefender.com/en-us/blog/labs/microsofts-mshta-legacy-malware-windows

Officially imported this from Bitdefender’s own source. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Bitdefender — imported from official source
Official source
https://www.bitdefender.com/blog/api/rss/labs/ RSS
Imported
September 20, 2026 19:52
Versions
1 recorded
Identity
6a0b1dc6a89a0404d6eab60a

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.