A new FileFix -like attack allows malicious scripts to be executed, bypassing Mark of the Web (MoTW) protection in Windows by exploiting the way browsers cache HTML web pages.
See also: Qantas: Cyberattack led to data breach

This technique was developed by security researcher mr.d0x. Last week, the researcher demonstrated how the original FileFix method works as an alternative approach to ClickFix, tricking users into pasting a disguised PowerShell command into the File Explorer address bar.
The attack involves a phishing website that tricks the victim into copying a malicious PowerShell command. Once pasted into File Explorer, Windows executes the PowerShell command, making the attack particularly subtle.
With the new variant of the FileFix attack, which bypasses MoTW, the attacker uses social engineering techniques to convince the user to save an HTML page (via Ctrl+S) and rename it to .HTA. This file automatically executes embedded JScript via mshta.exe.
HTML applications (.HTA) are now considered obsolete technology. However, this file type on Windows can be used to execute HTML and script content using the legitimate mshta.exe, under the permissions of the current user.
See also: New C4 attack bypasses AppBound cookie encryption
The researcher discovered that when HTML files are saved as “Webpage, Full” (with MIME type text/html), they do not receive the MoTW tag, thus allowing scripts to be executed without warning the user. When the victim opens the .HTA, the embedded malicious script is executed immediately, without any notification.

The most difficult and critical point of the attack is the social engineering stage, during which the victim must be convinced to save a web page and rename it.
One way to circumvent this obstacle is to create a more convincing decoy, such as a malicious website that prompts users to save backup verification (MFA) codes, supposedly to secure future access to a service.
The page will instruct the user to press Ctrl+S (Save As), select “Website, Complete” and save the file with the name 'MfaBackupCodes2025.hta'.
Although the FileFix attack that bypasses MoTW requires more interaction from the user, if the malicious website looks trustworthy and the user does not have sufficient knowledge about file extensions and security warnings, there is a high chance of being deceived.
See also: Microsoft Defender now blocks email bombing attacks
An effective defense strategy against this variant of the FileFix attack is to disable or completely remove the 'mshta.exe' file from your system. Additionally, it is recommended to enable the viewing of file extensions in Windows and block HTML attachments in emails.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
