Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Search Results: "mshta.exe"
Click on any threat for detailed analysis and mitigation recommendations
Threat actors exploited trusted brands and cloud services in a sophisticated web campaign combining fraudulent DocuSign workflows, Florida healthcare screening lures, and deceptive cloud infrastructure to deploy ConnectWise ScreenConnect Access clients. The attack utilized Cloudflare Pages hosting with fake Cloudflare verification workflows to establish legitimacy. Victims were socially engineered to download a ZIP archive containing a malicious HTA file that employed Base64-encoded VBScript, fake Adobe interfaces, UAC privilege escalation, and Microsoft Defender SmartScreen registry modifications. The attack leveraged living-off-the-land techniques using native Windows tools like mshta.exe, curl.exe, and msiexec.exe for silent ScreenConnect installation, ultimately providing unauthorized remote access. The campaign was classified as Zero Hour Fraudulent and blocked at the web entry point before payload delivery could occur. Join the discussion | AlienVault OTX General | 09/11/2026, 03:23:51 UTC Added: 09/11/2026, 14:47:25 UTC |
The npm package 'gptlite' version 4.0.8 contains malicious code in its preinstall lifecycle script. This script executes a Windows command that uses mshta.exe to fetch and run attacker-controlled code from an unauthenticated HTTP source (fixars.top) during installation. This results in arbitrary code execution on the installer's machine without user review. Join the discussion | GCVE Database | 07/13/2026, 17:38:10 UTC Added: 07/14/2026, 09:22:00 UTC |
APT-C-60 continues targeting organizations in Japan with evolved tactics observed throughout 2026. The threat group employs spear-phishing emails containing Proton Drive links or direct attachments with RAR archives. Victims extract LNK files that execute JavaScript via mshta.exe, leading to multi-stage payload delivery. The attackers abuse legitimate services including GitHub, GitLab, jsDelivr, and Codeberg as infrastructure for hosting malicious components. Git.exe is leveraged to execute scripts that deploy downloaders and loaders, ultimately delivering SpyGlace malware versions 3.1.15 through 3.1.18. The attack chain involves multiple obfuscated JavaScript files and persistence mechanisms similar to previous campaigns. By utilizing developer-oriented services and CDNs commonly allowed in corporate environments, the threat actor attempts to evade detection and blend malicious traffic with legitimate communications. Join the discussion | AlienVault OTX General | 07/13/2026, 12:54:54 UTC Added: 07/13/2026, 21:02:35 UTC |
The minigptcore npm package version 4.0.8 contains malicious code that executes during installation. Its preinstall script runs a Windows command to invoke mshta.exe, which fetches and executes an unverified HTA script from an external HTTP domain. This behavior allows remote code execution with the privileges of the user running npm install. The package metadata is minimal and generic, indicating a likely throwaway malicious upload. Join the discussion | GCVE Database | 07/13/2026, 06:54:44 UTC Added: 07/13/2026, 09:19:24 UTC |
The gptcore npm package versions 4.0.6, 4.0.7, and 4.0.8 include a malicious preinstall script that executes a Windows command to launch mshta.exe and fetch code from an untrusted remote HTTP URL. This causes arbitrary HTA/JScript content from the remote host to run on the installer's machine during npm install. The remote content is unrelated to the package's documented purpose and is fetched without integrity verification or publisher trust. Join the discussion | GCVE Database | 07/12/2026, 20:45:48 UTC Added: 07/13/2026, 09:21:11 UTC |
The sqligen package on PyPI contains malicious code that executes a remote payload during installation on Windows systems. The setup.py file includes obfuscated code that triggers execution of a remote HTA file via mshta.exe, resulting in arbitrary code execution under the installing user's privileges. This malicious behavior is hidden behind misleading variable names and encoding to evade detection. The threat affects multiple specific versions of sqligen and is classified as critical due to the potential for remote code execution. Join the discussion | GCVE Database | 06/26/2026, 09:23:52 UTC Added: 06/26/2026, 22:05:43 UTC |
The openblox PyPI package versions 1.0.0 and 1.0.1 contain malicious code that executes during installation. The setup.py script runs a function that constructs and executes a command to launch mshta.exe with a remote URL, causing the download and execution of remote malicious code. The package masquerades as a Roblox-related library but actually contains unrelated code and obfuscated commands to evade detection. Join the discussion | GCVE Database | 06/26/2026, 04:51:49 UTC Added: 06/26/2026, 22:05:37 UTC |
The TestPGAgent PyPI package versions 0.1 and 0.2 contain malicious code that executes during installation. The setup.py script uses base64-encoded obfuscated code to launch Windows mshta.exe to fetch and run a remote HTML application from an attacker-controlled HTTP server. This allows arbitrary code execution on any Windows machine installing these package versions. The malicious payload is unpinned, mutable, and unrelated to the declared publisher, indicating clear malicious intent. Join the discussion | GCVE Database | 06/15/2026, 17:24:46 UTC Added: 07/09/2026, 09:39:43 UTC |
SideCopy APT, a Pakistan-linked threat group under the Transparent Tribe umbrella, executed a targeted spear phishing campaign against Afghanistan's Ministry of Finance and provincial revenue directorates. The attack begins with a Pashto-language LNK file disguised as a staff directory document, which executes mshta.exe to fetch remote HTA payloads from compromised Afghan education infrastructure. The multi-stage chain deploys obfuscated JavaScript, establishes registry-based persistence mimicking Microsoft Edge, and ultimately delivers XenoRAT 1.8.7 beaconing to bulletproof Bulgarian hosting. The campaign demonstrates precise knowledge of target administrative context, using Dari and Pashto decoy documents listing provincial finance officials with direct contact information. Infrastructure analysis reveals deliberate staging within Afghan government IP space and C2 infrastructure overlapping with previous SideCopy operations. Join the discussion | AlienVault OTX General | 05/29/2026, 10:49:19 UTC Added: 05/29/2026, 12:33:32 UTC |
A multi-stage malware execution chain originating from a ClickFix lure has been discovered, leading to the delivery of infostealing malware like LummaC2 and Rhadamanthys. The campaign utilizes steganography to hide malicious code within PNG images. Two distinct ClickFix lures were observed: a standard 'Human Verification' and a convincing fake Windows Update screen. The execution chain involves mshta.exe, PowerShell, and .NET assemblies, ultimately extracting and injecting shellcode into target processes. The steganographic technique encodes malicious data directly into image pixel data, using specific color channels for payload reconstruction and decryption in memory. This sophisticated approach helps evade signature-based detection and complicates analysis. Join the discussion | AlienVault OTX General | 11/24/2025, 21:10:01 UTC Added: 11/25/2025, 09:13:18 UTC |
Showing 1 to 10 of 11 results