• HTML smuggling

Tactic or Technique: HTML smuggling

HTML smuggling is a stealthy way for attackers to deliver malware by hiding it inside HTML files either in emails or linked web pages. Instead of attaching a file directly, the attacks use JavaScript to build the malicious payload inside your browser after it’s already passed through security filters encoded or encrypted.
The trick works because the email or link doesn’t look dangerous on its own. Security tools see harmless HTML and JavaScript, but once you open the file or click the link, your browser assembles and downloads the real malware—completely bypassing traditional scans.
Attackers often use this to deliver ransomware, credential harvesters, or remote access tools. The malicious code is usually Base64-encoded or obfuscated in the HTML, then decoded and executed using legitimate browser functions. It’s been used in targeted campaigns against businesses, especially when attackers want to avoid detection while still delivering high-impact payloads.
Detection Methods (9):
File analysis
HTML analysis
Javascript analysis
Sender analysis
Content analysis
Archive analysis
Header analysis
URL analysis
YARA
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: HTML smuggling with eval and atob via calendar invite
15d ago
Jun 3rd, 2025 UTC
Sublime Security
Credential Phishing
Malware/Ransomware
Evasion
HTML smuggling
Scripting
File analysis
HTML analysis
Javascript analysis
/feeds/core/detection-rules/attachment-html-smuggling-with-eval-and-atob-via-calendar-invite-597c2edd
Attachment: HTML smuggling with atob and high entropy via calendar invite
15d ago
Jun 3rd, 2025 UTC
Sublime Security
Credential Phishing
Malware/Ransomware
Evasion
HTML smuggling
Scripting
File analysis
HTML analysis
Javascript analysis
Sender analysis
/feeds/core/detection-rules/attachment-html-smuggling-with-atob-and-high-entropy-via-calendar-invite-94d84614
Attachment: EML with Suspicious Indicators
16d ago
Jun 2nd, 2025 UTC
Sublime Security
Credential Phishing
Evasion
HTML smuggling
Social engineering
Content analysis
File analysis
/feeds/core/detection-rules/attachment-eml-with-suspicious-indicators-deb5d08d
Attachment: Web Files With Suspicious Comments
1mo ago
Apr 28th, 2025 UTC
Sublime Security
Credential Phishing
Malware/Ransomware
HTML smuggling
Evasion
File analysis
HTML analysis
Content analysis
/feeds/core/detection-rules/attachment-web-files-with-suspicious-comments-93061d17
Attachment: HTML with obfuscation and recipient's email in JavaScript strings
2mo ago
Apr 10th, 2025 UTC
Sublime Security
Credential Phishing
HTML smuggling
Scripting
Archive analysis
File analysis
HTML analysis
Javascript analysis
/feeds/core/detection-rules/attachment-html-with-obfuscation-and-recipients-email-in-javascript-strings-1aff486b
HTML smuggling containing recipient email address
2mo ago
Apr 1st, 2025 UTC
Sublime Security
Credential Phishing
Malware/Ransomware
Evasion
HTML smuggling
Scripting
Archive analysis
File analysis
Sender analysis
/feeds/core/detection-rules/html-smuggling-containing-recipient-email-address-af32ff2f
Attachment: EML file with HTML attachment (unsolicited)
2mo ago
Mar 28th, 2025 UTC
Sublime Security
Credential Phishing
Malware/Ransomware
Evasion
HTML smuggling
Content analysis
File analysis
Header analysis
HTML analysis
Sender analysis
/feeds/core/detection-rules/attachment-eml-file-with-html-attachment-unsolicited-c24fd191
Attachment: HTML file with excessive 'const' declarations and abnormally long timeouts
4mo ago
Feb 3rd, 2025 UTC
Sublime Security
Malware/Ransomware
Credential Phishing
HTML smuggling
Scripting
Evasion
HTML analysis
File analysis
Content analysis
/feeds/core/detection-rules/attachment-html-file-with-excessive-const-declarations-and-abnormally-long-timeouts-66f8a07a
Attachment: HTML With Emoji-to-Character Map
6mo ago
Dec 2nd, 2024 UTC
Sublime Security
Credential Phishing
Evasion
HTML smuggling
Impersonation: Brand
Scripting
Social engineering
File analysis
HTML analysis
Javascript analysis
Sender analysis
/feeds/core/detection-rules/attachment-html-with-emoji-to-character-map-3119d086
Attachment: HTML smuggling with atob and high entropy
9mo ago
Aug 29th, 2024 UTC
Sublime Security
Credential Phishing
Malware/Ransomware
HTML smuggling
Scripting
Archive analysis
Content analysis
File analysis
HTML analysis
Javascript analysis
Sender analysis
URL analysis
/feeds/core/detection-rules/attachment-html-smuggling-with-atob-and-high-entropy-03fcac11
Attachment: HTML smuggling with excessive string concatenation and suspicious patterns
9mo ago
Aug 27th, 2024 UTC
Sublime Security
Credential Phishing
Evasion
HTML smuggling
Scripting
Social engineering
File analysis
HTML analysis
Javascript analysis
/feeds/core/detection-rules/attachment-html-smuggling-with-excessive-string-concatenation-and-suspicious-patterns-e34fce8d
Low reputation link to auto-downloaded HTML file with smuggling indicators
1y ago
May 9th, 2024 UTC
Sublime Security
Credential Phishing
Evasion
Free file host
Free subdomain host
HTML smuggling
Impersonation: Brand
Open redirect
Social engineering
Content analysis
File analysis
HTML analysis
Javascript analysis
Sender analysis
URL analysis
/feeds/core/detection-rules/low-reputation-link-to-auto-downloaded-html-file-with-smuggling-indicators-339676c6
Attachment: HTML file with reference to recipient and suspicious patterns
1y ago
May 3rd, 2024 UTC
Sublime Security
Credential Phishing
HTML smuggling
Scripting
Content analysis
File analysis
HTML analysis
Javascript analysis
YARA
/feeds/core/detection-rules/attachment-html-file-with-reference-to-recipient-and-suspicious-patterns-5333493d
Attachment: HTML smuggling with decimal encoding
1y ago
Apr 23rd, 2024 UTC
Sublime Security
Credential Phishing
Malware/Ransomware
Evasion
HTML smuggling
Scripting
Archive analysis
Content analysis
File analysis
HTML analysis
/feeds/core/detection-rules/attachment-html-smuggling-with-decimal-encoding-f99213c4
Attachment: Any HTML file (untrusted sender)
1y ago
Apr 23rd, 2024 UTC
Sublime Security
HTML smuggling
HTML analysis
Sender analysis
/feeds/core/detection-rules/attachment-any-html-file-untrusted-sender-57a8f5c5
Attachment: Any HTML file (unsolicited)
1y ago
Apr 23rd, 2024 UTC
Sublime Security
HTML smuggling
File analysis
HTML analysis
Sender analysis
/feeds/core/detection-rules/attachment-any-html-file-unsolicited-ef36763f
Attachment: HTML Attachment with Login Portal Indicators
1y ago
Apr 23rd, 2024 UTC
@ajpc500
Credential Phishing
HTML smuggling
Scripting
Archive analysis
File analysis
HTML analysis
Javascript analysis
Sender analysis
/feeds/core/detection-rules/attachment-html-attachment-with-login-portal-indicators-3aabf4a7
Attachment: HTML smuggling with embedded base64-encoded executable
1y ago
Mar 25th, 2024 UTC
Sublime Security
Malware/Ransomware
Evasion
HTML smuggling
Archive analysis
File analysis
HTML analysis
YARA
/feeds/core/detection-rules/attachment-html-smuggling-with-embedded-base64-encoded-executable-b00c4527
Attachment: Archive containing HTML file with file scheme link
1y ago
Mar 7th, 2024 UTC
Sublime Security
Credential Phishing
Evasion
Exploit
HTML smuggling
Social engineering
Archive analysis
File analysis
HTML analysis
/feeds/core/detection-rules/attachment-archive-containing-html-file-with-file-scheme-link-edf6d0d9
CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
1y ago
Feb 23rd, 2024 UTC
Sublime Security
Malware/Ransomware
Evasion
Exploit
HTML smuggling
Scripting
Content analysis
HTML analysis
Sender analysis
/feeds/core/detection-rules/cve-2023-5631-roundcube-webmail-xss-via-crafted-svg-8405d61b