Fortra Intelligence and Research Experts (FIRE) are tracking an active phishing campaign, first observed in June, that uses HTA malware to gather detailed intelligence about a victim’s device before determining which payload to deploy next.
Rather than immediately delivering malware, the campaign performs reconnaissance on infected systems, collecting information such as OS, BIOS, and user details that can be used to tailor subsequent attack stages. Researchers found the operation combines HTA malware delivered via mshta.exe with off-screen execution, HTML smuggling, and polymorphic payloads designed to complicate detection.
The campaign appears focused on Spanish-speaking users and organizations, using invoice and judicial-notice phishing lures, while the infrastructure remains active and continues distributing updated samples.
https://www.fortra.com/resources/guides/active-campaign-distributing-hta-malware-payloads
Related
This entry was posted on September 10, 2026 at 1:26 pm and is filed under Commentary with tags Fortra. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Fortra researchers track phishing campaign that profiles victims before deploying malware
Fortra Intelligence and Research Experts (FIRE) are tracking an active phishing campaign, first observed in June, that uses HTA malware to gather detailed intelligence about a victim’s device before determining which payload to deploy next.
Rather than immediately delivering malware, the campaign performs reconnaissance on infected systems, collecting information such as OS, BIOS, and user details that can be used to tailor subsequent attack stages. Researchers found the operation combines HTA malware delivered via mshta.exe with off-screen execution, HTML smuggling, and polymorphic payloads designed to complicate detection.
The campaign appears focused on Spanish-speaking users and organizations, using invoice and judicial-notice phishing lures, while the infrastructure remains active and continues distributing updated samples.
https://www.fortra.com/resources/guides/active-campaign-distributing-hta-malware-payloads
Share this:
Like this:
Related
This entry was posted on September 10, 2026 at 1:26 pm and is filed under Commentary with tags Fortra. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.