PULSE NAME
IOC - Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows
WHITE celestre 2026-05-20 Modified: 2026-05-20
166
IOCs
HIGH VOLUME
Cybercriminals abuse legitimate, albeit legacy, tools to push a host of malware, ranging from run-of-the-mill password stealers to advanced threats. Bitdefender’s previous investigations already revealed how attackers used LOTL tactics in a Windows and macOS malware campaign that leveraged fake “Claude Code” Google ads.
Indicators of Compromise (1 / 166 total)
All domain FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 dbf37b54acb5e3b86a3dc93ec3b7dc24 MD5 of aa845a8fb4ab38aebe6a16a2a8f80ca4467ac0991d3eef4d8a10bdf97dedb1e9 2026-05-20