‘This reveals a broader security problem’: Experts warn that a key Microsoft tool is still being misused to launch malware campaigns.


  • Bitdefender is reporting increasing misuse of the old MSHTA utility to spread information-stealing and loading malware.
  • Campaigns range from simple commodity threats like LummaStealer to advanced persistence tools like PurpleFox.
  • Defenders are advised to restrict outdated scripting utilities and deploy layered security controls to detect malicious scripting activity.

Cybercriminals are increasingly using an old, legitimate Windows tool to deploy information-stealing and loading malware, researchers say.

A new Bitdefender report claims that since the start of 2026, there has been an uptick in activity related to a Windows utility called Microsoft HTML Application Host (MSHTA), a legitimate utility that runs special HTML application files called HTA.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top