HTA Epsilon Red Ransomware: How Fake Verification Pages Deliver It and How to Stay Safe

In July 2026, cybersecurity researchers uncovered a new ransomware campaign using weaponized .HTA (HTML Application) files disguised as fake verification pages to spread the Epsilon Red ransomware. These pages, designed to mimic platforms like Discord, Twitch, Kick, and OnlyFans, trick users into clicking a “Verify” button. Once clicked, the page executes malicious scripts using ActiveX controls through Internet Explorer’s engine. These scripts download and run ransomware directly into the system without alerting users. The ransomware encrypts data, leaves a ransom note, and bypasses modern security protections like SmartScreen and antivirus tools. Victims are advised to disable ActiveX, block suspicious domains, and avoid unknown verification prompts.

Jul 28, 2025 - 16:52
Updated: 2 days ago
103.3k
HTA Epsilon Red Ransomware: How Fake Verification Pages Deliver It and How to Stay Safe

Quick answer: The.HTA Epsilon Red campaign uses fake ClickFix verification pages, themed on sites such as Discord, Twitch and OnlyFans, to trick users into running an HTA file. A hidden script then downloads Epsilon Red ransomware. A genuine captcha never asks you to download or run anything, so close the page.

Key takeaways

  • Researchers described fake verification pages that run an.HTA file and download Epsilon Red ransomware.
  • A real captcha never asks you to download a file or run a command.
  • Block mshta.exe and.hta files, and alert on browsers spawning cmd.exe or curl.
  • Keep offline backups and report incidents in India to CERT-In.

What the campaign is

In July 2025, researchers at CloudSEK described a campaign that tricks people into running an.HTA file, which then downloads and starts Epsilon Red ransomware. The lure is a fake "verification" page, in the style known as ClickFix. Their write-up is here: CloudSEK analysis of the HTA and Epsilon Red campaign.

Three terms are worth knowing:

  • HTA (HTML Application): a Windows file type that runs web-page code with the permissions of the logged-in user, outside the browser's sandbox. It is opened by mshta.exe.
  • ClickFix: a social-engineering pattern in which a fake error or verification page asks the victim to take an action that actually runs the attacker's code.
  • Epsilon Red: a ransomware family first seen in 2021 that encrypts files. CloudSEK noted its ransom note resembles the REvil note, while the malware is otherwise separate.

How the attack works

According to CloudSEK, the lures imitated verification pages for services such as the Discord captcha bot, Twitch, Kick, Rumble, OnlyFans and dating sites. The chain they described is:

  1. The victim lands on a themed page and is asked to click a "verify" button.
  2. That leads to a second page with malicious JavaScript.
  3. The script uses ActiveXObject("WScript.Shell") to run hidden commands through cmd.exe.
  4. A command downloads an executable from an attacker server and runs it with the window hidden.
  5. The page shows a fake verification code so the victim believes the check worked.
  6. The executable is the ransomware, which then encrypts files.

The page is designed so that nothing looks wrong. The user "passed" a captcha and moves on while the damage starts.

Why it works

  • People are used to captchas and verification prompts and click through them.
  • HTA files and Windows Script Host give attackers a way to run code without a classic exploit.
  • Platforms such as Discord and streaming sites are used by young people and gamers, who may use personal devices with fewer protections.

Indicators to check

These are taken from the researchers' report. Always get the current list from the original source because indicators age quickly.

  • A browser spawning mshta.exe or cmd.exe.
  • Hidden command windows that run curl to fetch an executable.
  • Downloads of .hta files or unexpected prompts to open one.
  • Outbound connections to the IP addresses listed in the CloudSEK report.

How to protect yourself

For individuals:

  • A genuine captcha never asks you to download a file, open an.HTA, or paste or run anything. Close the page.
  • Do not open files you did not expect. Check the extension. Windows hides extensions by default; turn the setting on in File Explorer.
  • Keep Windows and your security software updated, and keep automatic protection on.
  • Keep an offline or cloud backup that ransomware cannot reach, so you can restore without paying.
  • Use a standard user account for daily work, not an administrator account.

For administrators:

  • Block or restrict .hta files and mshta.exe, for example with application control or attack surface reduction rules where available.
  • Consider disabling Windows Script Host for users who do not need it, through Group Policy.
  • Create alerts for a browser starting mshta.exe, cmd.exe or curl as a child process.
  • Block known malicious addresses at the firewall and DNS, and use web filtering.
  • Run phishing and ClickFix awareness training with real examples.

If you think you ran it

  1. Disconnect the device from the network (Wi-Fi off, cable out) to limit spread.
  2. Do not restart it if files are still being encrypted unless your security team advises it.
  3. Tell your IT or security team. In India, organisations report incidents to CERT-In: CERT-In.
  4. Change passwords from a clean device and check other accounts.
  5. Restore from backup after the device is cleaned or rebuilt. Paying does not guarantee recovery and funds crime.

The bigger pattern

ClickFix has appeared in many forms, with fake "fix this error" pages that ask users to paste commands into the Run box or a terminal. The common thread is persuading the user to execute the attacker's code. Training people to recognise that request is the most durable defence.

Next steps

To learn how teams respond to incidents like this, see the ECIH incident handler course. Related reading: Kimsuky and ClickFix and SVG files and phishing.

Frequently Asked Questions

It is a campaign described by CloudSEK in which fake verification pages trick users into running an.HTA file, which downloads Epsilon Red ransomware that then encrypts files. The lures imitated platforms such as Discord and Twitch.

An HTML Application is a Windows file that runs web-page code with the user's permissions outside the browser sandbox, opened by mshta.exe. Attackers abuse it to run scripts that download malware.

ClickFix is a social-engineering technique where a fake error or verification page tells the victim to perform an action that actually runs the attacker's code, such as running a file or pasting a command.

A genuine captcha only asks you to click images or tick a box. If it asks you to download or open a file, press keys, or paste a command, close the page. Do not run anything it provides.

Restrict.hta files and mshta.exe, consider disabling Windows Script Host, alert on browsers launching cmd.exe or curl, block malicious addresses, keep tested offline backups and train staff on ClickFix lures.

Disconnect the device from the network, tell your IT or security team, avoid paying, change passwords from a clean device and restore from backup after cleaning. Indian organisations should report incidents to CERT-In.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.