Threat actors are exploiting the legitimate mshta.exe utility to execute malicious HTA files in Spanish-language phishing emails, enabling system reconnaissance and staged deployment of credential-stealing malware This article explores mshta exe phishing. . The campaign primarily targets Spanish-speaking users at global organizations through fake invoice and judicial-notice lures, including emails with subject lines like "Facturación" and "Aviso Judicial."

The messages originate from accounts hosted by Italian provider libero.it, using infrastructure from italiaonline.it. Hackers Exploit Windows Mshta.exe in Phishing Attacks Messages labeled as high-confidence phishing often receive a SCL: -1 value, enabling them to bypass Microsoft’s email security filters. The links pass through various services, including goo[. ]su, abrir[.

]link, and abre[. ]ai, before redirecting to a malicious delivery page hosted on archivogratuito[. ]online.

Because mshta.exe is commonly found on numerous Windows systems, attackers frequently exploit it as a living-off-the-land binary to bypass application controls and security monitoring. The HTA launcher manipulates its application window outside normal screen boundaries using window.moveTo(6823, 3940), effectively concealing its activity from the victim. The campaign employs phishing, off-screen HTA execution, obfuscated URLs, HTML smuggling, random filenames, and polymorphic executables to circumvent layered defenses.

EDR teams should search for mshta.exe in Downloads, Desktop, or AppData directories, particularly when off-screen window behavior is followed by script injection, WMI discovery, PowerShell execution, 7-Zip SFX activity, and outbound network connections. Detect 58% more threats with up-to-date intelligence from 16K+ organizations.