Execute an HTA payload using MShta

/static/assets/windows-logo.svg
Executes an HTA file containing a VBA script to spawn a new Pneuma agent. This technique loads Operator network config facts from a previously staged file.
locked
View Command

To view this TTPs command, you must be logged in with a professional or enterprise license.

Login

Test this TTP

Download Operator (1.7.1)
Test this TTP using one of our Operator chains
APT40 defense industry

2022-04-12

/static/assets/windows-logo.svg
Emulating APT40's multi-stage macro-enabled documents.