Switch language한국어
Back to the list

Anatomy of a Low-Detection Credential Phishing Campaign

TL;DR AI

Key summary

2 min read
  1. Researchers found a low-detection HTML phishing campaign disguised as a corporate invoice.

  2. The obfuscated .SHTML attachment ran in the browser, captured email and password fields, and collected geolocation data.

  3. Stolen data was exfiltrated to a command-and-control server, then the victim was redirected to a benign image to hide the attack.

  4. The sample evaded many antivirus tools, showing how HTML-only phishing can still defeat defenders and steal credentials.

Read the original