HomeSecurityInternet Explorer: Still running malware

Internet Explorer: Still running malware

Microsoft's outdated helper application, 'mshta.exe', a remnant of Internet Explorer, is still actively used in modern malware campaigns, years after the browser itself was retired. According to new research from Bitdefender, attackers continue to exploit the Microsoft HTML Application Host (MSHTA), a built-in Windows helper application capable of executing VBScript and JavaScript from local or remote files.

See also: Microsoft: Edge's "IE Mode" revamped after zero-day attacks

Internet Explorer
Internet Explorer: Still running malware

Despite Internet Explorer reaching end-of-life in 2022, MSHTA is pre-installed on Windows systems and is used as a 'living-off-the-land' (LOLBIN) binary to launch malware. “Even when companies retire older products, parts of their ecosystem can remain on Windows for years to support legacy workflows and business compatibility requirements,” the researchers explained in a blog post.

“ Malware often exploits trusted, pre-installed Windows binaries to execute malicious content based on software already present on the system. ” Microsoft did not immediately comment on the issue. Bitdefender researchers have observed MSHTA appearing in infection chains associated with commodity stealers such as LummaStealer and Amatera , multi-stage loaders such as CountLoader and Emmenhtal Loader , banking trojans including ClipBanker , and even the long-running PurpleFox malware family

One of the most active clusters analyzed by Bitdefender included CountLoader, an HTA-based loader that used MSHTA to deliver LummaStealer and Amatera infections. Attackers relied on fake software downloads, cracked applications, SEO-poisoned websites, and social engineering to lure victims into executing malicious payloads.

See also: Interlock Ransomware: Cisco FMC Zero-Day Exploit

Internet Explorer: Still running malware
Internet Explorer: Still running malware

Victims downloaded password-protected archive files containing legitimate-looking installers. But clicking on them would execute a legitimate Python interpreter accompanied by malicious scripts that ultimately launched a renamed copy of mshta.exe. The binary would then communicate with a C2 infrastructure hosting HTA payloads to retrieve next-stage malware.

Malicious users also ran Emmenhtal Loader campaigns that exploited fake CAPTCHA verification pages distributed via phishing messages on Discord.

Victims were tricked into copying malicious commands into the Windows Run dialog box under the guise of “proving you are human.” MSHTA executed encrypted HTA payloads in memory before launching PowerShell to retrieve additional malware, ultimately delivering LummaStealer in one analyzed case. A Windows tool that refuses to die Bitdefender’s findings suggest that MSHTA remains attractive because it meets several criteria that attackers like.

These include being signed by Microsoft, pre-installed on Windows, capable of running in memory, and still considered trustworthy in many environments.

Other sophisticated campaigns have also used it. Bitdefender analyzed PurpleFox which uses MSHTA to launch 'msiexec' commands that download MSI payloads presented as PNG images from remote IP addresses. PurpleFox, once installed, acts as a rootkit-enabled backdoor capable of persistence, monitoring, information theft, and distributed denial-of-service (DOS) activity.

See also: APT28 linked to MSHTML zero-day ahead of February Patch Tuesday

Internet Explorer: Still running malware
Internet Explorer: Still running malware

Elsewhere, ClipBanker campaigns used HTA loaders to execute Base64-encoded PowerShell commands that established persistence via scheduled tasks posing as legitimate Windows services. The malware eventually captured cryptocurrency wallet addresses that were copied to victims' clipboards. Bitdefender warned that not every execution of MSHTA is inherently malicious.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS