‘This exposes a wider security problem’: Experts warn that a key legacy Microsoft tool is still being misused to launch malware campaigns


  • Bitdefender reports increasing abuse of the legacy MSHTA tool to deliver info stealers and loader malware
  • Campaigns range from simple commodity threats like LummaStealer to advanced persistence tools like PurpleFox
  • Defenders are encouraged to restrict outdated scripting tools and implement layered security controls to detect malicious scripting activity

Cybercriminals are increasingly using a legitimate legacy Windows tool to deploy info stealers and loader malware, researchers say.

A new Bitdefender report has claimed that since the beginning of 2026 there has been an increase in activity related to a Windows tool called Microsoft HTML Application Host (MSHTA), a legitimate tool that runs special HTML-based application files known as HTAs.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top