logo

Analyzing CryptoJS Encrypted Phishing Attempt

ID: 4ae8f166-566f-5630-8724-4e65d618e667

STIX ID: report--4ae8f166-566f-5630-8724-4e65d618e667

Feed Name: Binary Defense Blog

Threat Score
55/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

ARC Labs analyzed a phishing credential-harvesting campaign that embedded obfuscated HTML/SVG and JavaScript (loaded CryptoJS remotely) to hide a second-stage credential collection page. The payload distributed encrypted data across multiple base64-encoded HTML classes, dynamically decrypted at runtime using a hardcoded passphrase, and was recoverable through code and runtime analysis to reveal the final malicious URL.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.