Campaign record
mshta lures fetching remote HTAs
Fake CAPTCHA pages serving remote HTML Applications through mshta
- Status as last assessed
- Active
- First seen
- Unrecorded
- Last seen
- 2025-05-19
- Indicators
- 6
- Sources
- 1
- Targets
- Windows
- Fake CAPTCHA verification
- Malvertising
- SEO poisoning
Original research
- Trend Micro2025-05-19Vendor researchFirst account
Fake CAPTCHA Attacks Deploy Infostealers and RATs in a Multistage Payload Chain
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
Alongside the audio-file cases, Trend Micro's incident data held a run of counterfeit verification pages whose common trait was simply the instruction to paste a line into a system prompt. Each page assembled that line in the browser, decoded it from base64 and placed it on the clipboard, so the visitor never read the destination. Most aimed mshta at a remote HTML Application on a short-lived domain; one used a hidden PowerShell instruction that retrieved a text file and evaluated its contents. Victims arrived through malvertising, through email, and in one investigated case through a poisoned search result for a stately-home visitor attraction, where the top-ranked link was a legitimate website that had been broken into. Trend Micro does not tie these particular hosts to any named malware family.
Execution mechanisms
How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.
| Mechanism | Across the corpus | ATT&CK |
|---|---|---|
| Windows Run dialog | 23 of 4452% | T1204.004 |
| PowerShell | 19 of 4443% | T1059.001 |
| mshta.exe | 7 of 4416% | T1218.005 |
All 3 of these mechanisms appear together in 3 of the 44 campaigns on record, this one included. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.
Indicators
6 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator. No observation date is recorded for any of them.
| Indicator | Type | Role | Assessment | Report an error |
|---|---|---|---|---|
| domain, shown defanged for safety: check dot nejyd dot icu | domain | Payload host | Not yet assessed | Report an error in domain record 04e16071-dd32-4817-94bf-15f07656c7a3 |
| url, shown defanged for safety: hxxp colon slash slash ok dot fish-cloud-jar dot us/ | url | Payload host | Not yet assessed | Report an error in url record 9ef8a93e-bbcf-4317-84cd-ba675770e230 |
| url, shown defanged for safety: hxxps colon slash slash w19-seasalt dot com/mbDjBsRmxM1LreEp dot html | url | Payload host | Not yet assessed | Report an error in url record a92d7aa0-2d22-488d-b568-0780059f7ba1 |
| url, shown defanged for safety: hxxps colon slash slash welcome12-world dot com/wpDoQRpZt2PIffud dot html | url | Payload host | Not yet assessed | Report an error in url record 00b67f38-e762-4c37-8c53-fbcdbb2eebd1 |
| url, shown defanged for safety: hxxps colon slash slash x63-hello dot live/nF3mXcQ9FVjs1sMt dot html | url | Payload host | Not yet assessed | Report an error in url record f973fad6-2781-4f12-a19c-d09dc17d7aba |
| domain, shown defanged for safety: fessoclick dot com | domain | Staging | Not yet assessed | Report an error in domain record 5f43685e-30d4-4aa1-b53e-ef23c7467dd4 |
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “mshta lures fetching remote HTAs”, campaign ID c0b21902, retrieved 2026-08-07, snapshot fb0eed7.
https://clickfixreport.com/campaigns/c0b21902/fake-captcha-mshta-hta-lures
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.