Tactic or Technique: HTML smuggling

HTML smuggling is a stealthy way for attackers to deliver malware by hiding it inside HTML files either in emails or linked web pages. Instead of attaching a file directly, the attacks use JavaScript to build the malicious payload inside your browser after it’s already passed through security filters encoded or encrypted.
The trick works because the email or link doesn’t look dangerous on its own. Security tools see harmless HTML and JavaScript, but once you open the file or click the link, your browser assembles and downloads the real malware—completely bypassing traditional scans.
Attackers often use this to deliver ransomware, credential harvesters, or remote access tools. The malicious code is usually Base64-encoded or obfuscated in the HTML, then decoded and executed using legitimate browser functions. It’s been used in targeted campaigns against businesses, especially when attackers want to avoid detection while still delivering high-impact payloads.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: SVG file with HTML entity encoded href attributes
10d ago
May 20th, 2026
Sublime Security
Attachment: HTML smuggling with eval and atob via calendar invite
1mo ago
Apr 28th, 2026
Sublime Security
Attachment: HTML smuggling with atob and high entropy via calendar invite
1mo ago
Apr 28th, 2026
Sublime Security
CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
1mo ago
Apr 27th, 2026
Sublime Security
Attachment: Double base64-encoded zip file in HTML smuggling attachment
1mo ago
Apr 27th, 2026
@ajpc500
Attachment: HTML smuggling Microsoft sign in
1mo ago
Apr 27th, 2026
Sublime Security
Credential Phishing: W-2 lure with inline SVG Windows logo
1mo ago
Apr 8th, 2026
Sublime Security
Attachment: Archive containing HTML file with file scheme link
2mo ago
Mar 17th, 2026
Sublime Security
Attachment: HTML smuggling with excessive line break obfuscation
4mo ago
Jan 12th, 2026
Sublime Security
Attachment: EML containing a base64 encoded script
4mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML file contains exclusively Javascript
4mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML attachment with login portal indicators
4mo ago
Jan 12th, 2026
@ajpc500
Attachment: HTML file with excessive padding and suspicious patterns
4mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML file with reference to recipient and suspicious patterns
4mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML smuggling with atob and high entropy
4mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML smuggling with auto-downloaded file
4mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML smuggling 'body onload' linking to suspicious destination
4mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML smuggling with concatenation obfuscation
4mo ago
Jan 12th, 2026
@vector_sec
Attachment: HTML smuggling with decimal encoding
4mo ago
Jan 12th, 2026
Sublime Security
Attachment: HTML smuggling with eval and atob
4mo ago
Jan 12th, 2026
Sublime Security