GB Hackers highlighted research from Aranzazu Casillas of the Fortra Intelligence and Research Experts (FIRE) team on an active phishing campaign that abuses Windows mshta.exe to execute malicious HTA files and support credential theft. The research details how attackers use Spanish-language phishing lures, HTML smuggling, and multi-stage malware delivery techniques to evade detection. The campaign has remained active since June, with operators regularly recompiling malware samples to generate new hashes and bypass signature-based defenses.
"Fortra’s Intelligence and Research Experts (FIRE) said the activity began in June and remains active, with operators regularly recompiling malware samples to generate new hashes and evade signature-based security controls."