New Wave of SHTML Phishing Attacks
ID: 2bda67e3-9ba4-5527-8b96-2ccf3021981d
STIX ID: report--2bda67e3-9ba4-5527-8b96-2ccf3021981d
Feed Name: McAfee Labs Blog
McAfee Labs observed a phishing campaign abusing server-parsed HTML (SHTML) email attachments that use JavaScript to display blurred fake documents and credential-harvesting forms; harvested data is exfiltrated via static form services (Formspree/Formspark) or by redirecting victims to malicious pages. The report contains analysis, code snippets, screenshots, mitigation advice, and IOCs (malicious URLs and SHTML file hashes), and notes that McAfee detections have blocked the identified indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
