Anatomy of a Low-Detection Credential Phishing Campaign

TL;DR AI
2 min readKey summary
Researchers found a low-detection HTML phishing campaign disguised as a corporate invoice.
The obfuscated .SHTML attachment ran in the browser, captured email and password fields, and collected geolocation data.
Stolen data was exfiltrated to a command-and-control server, then the victim was redirected to a benign image to hide the attack.
The sample evaded many antivirus tools, showing how HTML-only phishing can still defeat defenders and steal credentials.
