‘This reveals a broader security issue’: Experts warn a key Microsoft legacy tool is still being abused to launch malware campaigns



  • Bitdefender reports increasing abuse of legacy MSHTA utility to spawn infostealers and malware loaders
  • Campaigns range from simple commodity threats like LummaStealer to advanced persistence tools like PurpleFox.
  • Defenders are urged to restrict outdated script utilities and implement layered security controls to detect malicious script activity.

Researchers say cybercriminals are increasingly using a legitimate Windows legacy tool to deploy information stealers and malware loaders.

A new report from Bitdefender claims that since early 2026, there has been an increase in activity related to a Windows utility called Microsoft HTML Application Host (MSHTA), a legitimate utility that runs special HTML-based application files known as HTA.

Leave a Comment

Your email address will not be published. Required fields are marked *