HTML attachment

Winsage
September 23, 2024
A wave of cyberattacks has emerged, utilizing phishing emails that contain HTML attachments or malicious links. When recipients interact with these emails, a Java-based Remote Access Trojan (RAT) is deployed, allowing attackers to manage the victim's file system, monitor and control processes, remotely access the desktop, transfer files, capture keystrokes, take screenshots, and activate the webcam without the user's knowledge.
Winsage
June 13, 2024
Hackers are using Windows Search to deploy malware, with a sophisticated campaign that includes malicious HTML files disguised as normal documents in email attachments. Crafted search queries manipulate Windows Explorer to execute the search and abuse the search protocol, redirecting the browser using malicious HTML. Trustwave has updated its systems to identify and prevent these attacks, emphasizing the importance of user education and proactive security measures.
Winsage
June 13, 2024
The recent attacks described in the Trustwave report involve malicious emails with HTML attachments disguised as invoice documents in ZIP archives. The HTML file contains a meta refresh tag that opens a malicious URL, and if that fails, an anchor tag provides a clickable link to the URL. The URL uses the Windows Search protocol to perform a search on a remote host, displaying a fake interface to trick users. Clicking on a file in the search results triggers a batch script on the server. Trustwave recommends deleting registry entries associated with the search protocol to defend against this threat.
Search