Tactic or Technique: HTML smuggling

HTML smuggling is a stealthy way for attackers to deliver malware by hiding it inside HTML files either in emails or linked web pages. Instead of attaching a file directly, the attacks use JavaScript to build the malicious payload inside your browser after it’s already passed through security filters encoded or encrypted.
The trick works because the email or link doesn’t look dangerous on its own. Security tools see harmless HTML and JavaScript, but once you open the file or click the link, your browser assembles and downloads the real malware—completely bypassing traditional scans.
Attackers often use this to deliver ransomware, credential harvesters, or remote access tools. The malicious code is usually Base64-encoded or obfuscated in the HTML, then decoded and executed using legitimate browser functions. It’s been used in targeted campaigns against businesses, especially when attackers want to avoid detection while still delivering high-impact payloads.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: Archive containing HTML file with file scheme link
13d ago
Mar 17th, 2026
Sublime Security
Attachment: HTML smuggling with setTimeout
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML smuggling with eval and atob via calendar invite
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML smuggling with atob and high entropy via calendar invite
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML smuggling Microsoft sign in
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML smuggling with excessive line break obfuscation
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML smuggling with RC4 decryption
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: EML with suspicious indicators
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: EML file contains HTML attachment with login portal indicators
2mo ago
Jan 12th, 2026
Sublime Security
HTML smuggling with atob in message body
2mo ago
Jan 12th, 2026
Sublime Security
CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML smuggling with ROT13
2mo ago
Jan 12th, 2026
@Kyle_Parrish_
Attachment: HTML smuggling with unescape
2mo ago
Jan 12th, 2026
Sublime Security
Low reputation link to auto-downloaded HTML file with smuggling indicators
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML smuggling 'body onload' with high entropy and suspicious text
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: Any HTML file within archive (unsolicited)
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: EML containing a base64 encoded script
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML file contains exclusively Javascript
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML attachment with login portal indicators
2mo ago
Jan 12th, 2026
@ajpc500
Attachment: HTML file with excessive padding and suspicious patterns
2mo ago
Jan 12th, 2026
Sublime Security