logo

Hackers Using Sneaky HTML Smuggling to Deliver Malware via Fake Google Sites

ID: bbc18d04-16ec-5562-a630-3d633e27a1e9

STIX ID: report--bbc18d04-16ec-5562-a630-3d633e27a1e9

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-03-18

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers observed a widespread phishing campaign abusing Google Sites and HTML smuggling to distribute the AZORult information stealer (with a later analysis reattributing the payload to Koi Loader/Koi Stealer). The attack uses CAPTCHA-protected fake Google Docs pages to deliver LNK files disguised as PDF bank statements, which trigger PowerShell and batch script chains that fetch and execute loaders and the stealer via reflective, fileless techniques and AMSI bypass, aiming to harvest credentials, browser data, documents and cryptocurrency wallets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.