The attack
began after a user opened a malicious file, likely delivered through email or a browser download.
It launched
mshta.exe, a legitimate Windows utility, which
contacted attacker-controlled infrastructure to collect a remote payload and prepare persistent activity.
One flagged suspicious command activity connected to
RunMRU registry use, while a correlation engine judged the combined behavior to be malicious rather than normal administration.
The final
time from first detection to isolation was 128 seconds. The affected device lost internal and external network access, except for security-management traffic, ending its communication with the attacker-controlled service and leaving an auditable timeline.
A malicious file abused Windows mshta.exe to fetch a payload, enabling persistence, credential theft, and network compromise.
cybersecuritynews.com