Threats Tagged 'html smuggling'
View all threats tagged with 'html smuggling'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'html smuggling'
Click on any threat for detailed analysis and mitigation recommendations
Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle attacks. Analysis shows 63.7% of identified victims are in the US, with Technology, Manufacturing, and Education among the most targeted industries. The operation generated thousands of compromise events between 2024 and 2026, including stolen session cookies, passwords, and SSO access. Once a Microsoft 365 session is hijacked, attackers gain access to corporate email, sensitive data, and trusted business accounts. The toolkit uses browser-based delivery through .htm, .xhtml, and .svg stagers, QR codes, JavaScript obfuscation, and WebSocket-based AiTM activity. Of 9,426 unique targeted email addresses, 4,532 were potentially compromised, representing approximately 48% success rate. MediumCampaign Join the discussion | AlienVault OTX General | 08/18/2026, 20:48:20 UTC Added: 08/19/2026, 10:04:41 UTC |
Recent investigations have uncovered sophisticated phishing campaigns employing multi-stage redirection chains that abuse trusted cloud infrastructure and newly registered domains. One campaign exploits Framer, a no-code web platform, combined with Cloudflare Workers to host deceptive landing pages. These pages utilize HTML redirection smuggling via the Blob API, Web Crypto API for decryption, and anti-debugging techniques to evade detection. Another campaign involves device code phishing targeting OneDrive credentials through three-stage redirections using newly registered domains with randomized alphanumeric strings. Both campaigns employ brand impersonation, custom CAPTCHA challenges, and anti-analysis measures including keyboard shortcut blocking. The threat actors leverage a hybrid infrastructure combining legitimate cloud services with short-lived domains to bypass traditional detection methods. Join the discussion | AlienVault OTX General | 08/12/2026, 21:15:23 UTC Added: 08/13/2026, 09:56:23 UTC |
This past month, Trustwave SpiderLabs observed that HTML (Hypertext Markup Language) file attachments had become a common occurrence in our spam traps, which is not unusual since malware is often delivered through phishing spam. Join the discussion | AlienVault OTX General | 10/07/2022, 15:38:05 UTC Added: 09/26/2025, 12:24:45 UTC |
Showing 1 to 3 of 3 results