Deep Dive into mshta.exe: Abuse of a Windows Native Tool in the Attack Chain
mshta.exe is a legitimate, built-in Windows tool for running HTA applications; its high system privileges make it a favorite LOLBin loader for attackers. Using a copy-paste phishing case impersonating NotebookLM, this report breaks down how attackers load a remote HTA and reshape the process chain via a scheduled task to evade mshta-to-powershell detection, and catalogs forensic artifacts — RunMRU, PowerShell history, and Prefetch — that can reconstruct the activity.