Malicious mshta.exe Spawning bitsadmin via ClickFix Phantom Meet

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-07-29
Updated
2026-08-28

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects mshta.exe spawning bitsadmin.exe, the process chain produced by the ClickFix Phantom Meet campaign where a pasted clipboard command runs a remote HTA that then uses bitsadmin to download follow on executables. Neither mshta launching bitsadmin nor this fake meeting lure is normal user behavior. The parent child relationship is a high confidence detection of the ClickFix delivery chain.

Related detections9 linkedT1218.005 — drag to rearrange
Suspicious MSHTA VBScript WScript Shell Execution
Suspicious Remote HTA Payload Execution via MSHTA
BITS Job Persistence via Bitsadmin Notify Command (via process_creation)
Malicious Shell Spawned by Mshta Delivery (via process_creation)
BITS Payload Downloaded via Commandline (via process_creation)
Malicious Kimsuky Remote HTA Execution via URL Shortener (via process_creation)
ClickFix Paste-Jacking Execution of mshta Retrieving Remote Payload (via process_creation)
BITS Payload Downloaded via PowerShell (via powershell)
Suspicious mshta Execution of Remote HTA Payload
Malicious mshta.exe Spawning bitsadmin via ClickFix Phantom Meet
Pivot detection · T1218.005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.