HTA Epsilon Red Ransomware: How Fake Verification Pages Deliver It and How to Stay Safe
In July 2026, cybersecurity researchers uncovered a new ransomware campaign using weaponized .HTA (HTML Application) files disguised as fake verification pages to spread the Epsilon Red ransomware. These pages, designed to mimic platforms like Discord, Twitch, Kick, and OnlyFans, trick users into clicking a “Verify” button. Once clicked, the page executes malicious scripts using ActiveX controls through Internet Explorer’s engine. These scripts download and run ransomware directly into the system without alerting users. The ransomware encrypts data, leaves a ransom note, and bypasses modern security protections like SmartScreen and antivirus tools. Victims are advised to disable ActiveX, block suspicious domains, and avoid unknown verification prompts.
Quick answer: The.HTA Epsilon Red campaign uses fake ClickFix verification pages, themed on sites such as Discord, Twitch and OnlyFans, to trick users into running an HTA file. A hidden script then downloads Epsilon Red ransomware. A genuine captcha never asks you to download or run anything, so close the page.
Key takeaways
- Researchers described fake verification pages that run an.HTA file and download Epsilon Red ransomware.
- A real captcha never asks you to download a file or run a command.
- Block mshta.exe and.hta files, and alert on browsers spawning cmd.exe or curl.
- Keep offline backups and report incidents in India to CERT-In.
What the campaign is
In July 2025, researchers at CloudSEK described a campaign that tricks people into running an.HTA file, which then downloads and starts Epsilon Red ransomware. The lure is a fake "verification" page, in the style known as ClickFix. Their write-up is here: CloudSEK analysis of the HTA and Epsilon Red campaign.
Three terms are worth knowing:
- HTA (HTML Application): a Windows file type that runs web-page code with the permissions of the logged-in user, outside the browser's sandbox. It is opened by
mshta.exe. - ClickFix: a social-engineering pattern in which a fake error or verification page asks the victim to take an action that actually runs the attacker's code.
- Epsilon Red: a ransomware family first seen in 2021 that encrypts files. CloudSEK noted its ransom note resembles the REvil note, while the malware is otherwise separate.
How the attack works
According to CloudSEK, the lures imitated verification pages for services such as the Discord captcha bot, Twitch, Kick, Rumble, OnlyFans and dating sites. The chain they described is:
- The victim lands on a themed page and is asked to click a "verify" button.
- That leads to a second page with malicious JavaScript.
- The script uses
ActiveXObject("WScript.Shell")to run hidden commands throughcmd.exe. - A command downloads an executable from an attacker server and runs it with the window hidden.
- The page shows a fake verification code so the victim believes the check worked.
- The executable is the ransomware, which then encrypts files.
The page is designed so that nothing looks wrong. The user "passed" a captcha and moves on while the damage starts.
Why it works
- People are used to captchas and verification prompts and click through them.
- HTA files and Windows Script Host give attackers a way to run code without a classic exploit.
- Platforms such as Discord and streaming sites are used by young people and gamers, who may use personal devices with fewer protections.
Indicators to check
These are taken from the researchers' report. Always get the current list from the original source because indicators age quickly.
- A browser spawning
mshta.exeorcmd.exe. - Hidden command windows that run
curlto fetch an executable. - Downloads of
.htafiles or unexpected prompts to open one. - Outbound connections to the IP addresses listed in the CloudSEK report.
How to protect yourself
For individuals:
- A genuine captcha never asks you to download a file, open an.HTA, or paste or run anything. Close the page.
- Do not open files you did not expect. Check the extension. Windows hides extensions by default; turn the setting on in File Explorer.
- Keep Windows and your security software updated, and keep automatic protection on.
- Keep an offline or cloud backup that ransomware cannot reach, so you can restore without paying.
- Use a standard user account for daily work, not an administrator account.
For administrators:
- Block or restrict
.htafiles andmshta.exe, for example with application control or attack surface reduction rules where available. - Consider disabling Windows Script Host for users who do not need it, through Group Policy.
- Create alerts for a browser starting
mshta.exe,cmd.exeorcurlas a child process. - Block known malicious addresses at the firewall and DNS, and use web filtering.
- Run phishing and ClickFix awareness training with real examples.
If you think you ran it
- Disconnect the device from the network (Wi-Fi off, cable out) to limit spread.
- Do not restart it if files are still being encrypted unless your security team advises it.
- Tell your IT or security team. In India, organisations report incidents to CERT-In: CERT-In.
- Change passwords from a clean device and check other accounts.
- Restore from backup after the device is cleaned or rebuilt. Paying does not guarantee recovery and funds crime.
The bigger pattern
ClickFix has appeared in many forms, with fake "fix this error" pages that ask users to paste commands into the Run box or a terminal. The common thread is persuading the user to execute the attacker's code. Training people to recognise that request is the most durable defence.
Next steps
To learn how teams respond to incidents like this, see the ECIH incident handler course. Related reading: Kimsuky and ClickFix and SVG files and phishing.
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0