Actualidad ISAC

 
Alerta

Los piratas informáticos abusan de la herramienta heredada de Windows de MSHTA para distribuir malware LummaStealer y Amatera

Resumen Informativo

🏷 Tags:PHISHINGMALWAREEXPLOITINGENIERíA SOCIALCREDENCIALESRCE
Nivel de riesgo estimado: Alto

De acuerdo a la publicación titulada Los piratas informáticos abusan de la herramienta heredada de Windows de MSHTA para distribuir malware LummaStealer y Amatera, difundida en fecha 20/05/2026 11:23, por el medio Cybersecuritynews (Autor: Tushar Subhra Dutta):

Los actores de amenazas están explotando una herramienta legacy de Windows con décadas de antigüedad para distribuir malware en sistemas desprevenidos, con impactos que van desde el robo de contraseñas hasta el compromiso total del sistema. La herramienta es MSHTA, abreviatura de Microsoft HTML Application Host, una utilidad integrada de Windows que puede ejecutar scripts desde archivos locales o remotos.

Los atacantes la han estado utilizando para distribuir algunos de los programas maliciosos más utilizados en la actualidad, incluidos LummaStealer y Amatera.

Los actores de amenazas abusan de la herramienta heredada de Windows MSHTA. Las campañas observadas cubren varias familias de malware, incluidas LummaStealer, Amatera, ClipBanker, CountLoader, Emmenhtal Loader y PurpleFox. Lo que hace que la situación sea particularmente grave es que MSHTA viene habilitado por defecto en Windows sin un cronograma de eliminación anunciado. Una de las cadenas de infección más activas involucra un loader llamado CountLoader, que usa MSHTA para entregar LummaStealer y Amatera.

Los atacantes envían mensajes de phishing en Discord con enlaces a páginas de verificación falsas que imitan sistemas reCAPTCHA. La publicación Los actores de amenazas abusan de la herramienta heredada de Windows MSHTA para distribuir LummaStealer y Amatera Malware apareció por primera vez en Cyber Security News.

🛡️Indicadores de Compromiso (IoC)Extraídos automáticamente — verificar antes de usar
Dominios
google-services[.]ccmemory-scanner[.]ccexplorer[.]vgccleaner[.]glcapcha[.]htmlemdenek[.]local-wanderer[.]shopriwz[.]mpbuck2nd[.]oss-eu-central-1[.]aliyuncs[.]comsingl6[.]mpmacphotoeditor[.]shopsingl5[.]mptopofsuper[.]shopre5[.]mpantibot-check[.]icucheckpageonce[.]comechoicedeals[.]shops6[.]mpkizmond[.]shopriiw1[.]mpklipjaqemiu[.]shopweb44[.]mponceletthemcheck[.]compawpaws[.]readit-carfanatics[.]commadonna[.]mppropofgustestyle[.]inforecaptcha-verify[.]htmlemrecaptcha-process[.]comretrosome[.]shopru2-2[.]emlemmsavecoupons[.]stores7[.]mpsolve[.]gevaqawjxs[.]captchsolve[.]jenjthepremiumstuffs[.]shops5[.]mptriptrip[.]melody-wave[.]shopre2[.]mpcheck[.]qlkwrawjsx[.]captchdriftcharm[.]shopetrademart[.]shopscrutinycheck[.]cashsimplerwebs[.]spaceanrek[.]mpsimplerwebs[.]worldmine[.]jsonemtypeindicatordescriptiondomainmemory-scanner[.]cccouninfrastructuredomainfileless-market[.]cccouninfrastructuredomainhell1-kitty[.]cccouninfrastructuredomainholiday-forever[.]cccouninfrastructuredomainsystem-monitor[.]cccouninfrastructuredomainforest-entity[.]cccouninfrastructuredomainindeanapolice[.]cccouninfrastructuredomainfiles-storage[.]cccouninfrastructuredomainsome-othertag[.]cccouninfrastructuredomains3-updatehub[.]cccouninfrastructuredomains3-microservice-updatehub[.]cccouninfrastructuredomainmicroservice-update-s2-bucket[.]cccouninfrastructuredomainparent-control[.]cccouninfrastructuredomainalphazero1-endscape[.]cccouninfrastructuredomainmicroservice-update-s1-bucket[.]cccouninfrastructuredomainglobalsnn2-new[.]cccouninfrastructuredomainpolystore9-servicebucket[.]cccouninfrastructuredomainhardware-office[.]cccouninfrastructuredomainimmortal-service[.]cccouninfrastructuredomainglobalsnn1-new[.]cccouninfrastructuredomainacio-patron[.]cccouninfrastructuredomainhell2-kitty[.]cchell10-kitty[.]cccouninfrastructuredomainalpha-centavr[.]cccouninfrastructuredomainazure-s3-bucket[.]cccouninfrastructuredomainhosting-control[.]cccouninfrastructuredomaincommunicationfirewall-security[.]cccouninfrastructuredomaindomain-monitoring[.]cccouninfrastructuredomainnetwork-defender[.]cccouninfrastructuredomaincritical-service[.]cccouninfrastructuredomaingoogle-services[.]cccouninfrastructuredomainoffshore-storage[.]cccouninfrastructuredomainuruguvai[.]cccouninfrastructuredomainweb3-walletnotify[.]cccouninfrastructuredomaindebank-api[.]cccouninfrastructuredomainpy-installer[.]cccouninfrastructuredomainmemory-protection-layer1[.]cccouninfrastructuredomains1-microservice-updatehub[.]ccs10-microservice-updatehub[.]cccouninfrastructuredomainsentinel1-endpoint-security[.]cccouninfrastructuredomainfileless-storage-s3[.]cccouninfrastructuredomainms-team-ping6[.]comcouinfrastructuredomainholiday-updateservice[.]comcouinfrastructuredomainhealth-smooth-eu2[.]comcouinfrastructuredomainhealth-smooth-eu3[.]comcouinfrastructuredomainbigbrainsholdings[.]comcouinfrastructuredomainmy-smart-house1[.]comcouinfrastructuredomainexplorer[.]vgnewinfrastructuredomainccleaner[.]glnewinfrastructuredomainmicroservice[.]glnewinfrastructuredomaingeo-foundation[.]vgnewinfrastructuredomaindeluxe[.]glnewinfrastructuredomainsilverhost[.]vgnewinfrastructuredomainmsgrouppolicy[.]vgnewinfrastructuredomainholypriest[.]glnewinfrastructuredomainmsedge[.]vgnewd6shiiwz[.]pwd6[.]htahtas7610rir[.]pwchecking[.]htahtad1[.]pool4883[.]pwr7[.]htahtaus1[.]somepools555[.]pw

⚠️ Dominios y URLs defangeados ([.] / hxxp) para prevenir activación accidental de enlaces maliciosos.


📌 Cita formal

Fuente: Cybersecuritynews
Título original: Los piratas informáticos abusan de la herramienta heredada de Windows de MSHTA para distribuir malware LummaStealer y Amatera
Publicado: 20/05/2026 11:23
Enlace: https://cybersecuritynews.com/hackers-abuse-mshta-legacy-windows-tool
Consultado: 20/05/2026

Consultar publicación original ↗

Anterior
Siguiente