The Proportion of Malicious HTML Attachments Doubles Within a year

The security industry has been highlighting the cybercriminal misuse of HTML for years — and evidence suggests it remains a successful and popular attack tool. Barracuda’s analysis shows that in the ten months from May 2022 to March 2023, the proportion of malicious attack attachments among HTML attachments more than doubled, from 21% to 45.7%.

What are HTML attachments?

HTML stands for Hypertext Markup Language and it is used to create and structure content displayed online. HTML is also commonly used in e-mail communications, such as automated reports that users may receive on a regular basis, such as newsletters, marketing materials, etc. In many cases, reports are attached to an email in HTML format (with the file extension .html, .htm, or .xhtml, for example).

People are generally less suspicious if the email appears to be from a known or trusted brand. However, attackers are tricking users by using carefully crafted “official” emails with HTML attachments. If the recipient opens the HTML file, they are taken to a phishing site or other malicious content controlled by the attacker, where the user is asked to enter their credentials to access the information or download a file that may contain malware. Since the HTML attachment itself is not malicious, the attacker does not include malware in the attachment but uses a Javascript library hosted elsewhere to perform multiple redirects, so this type of attack is difficult to detect. Even in some cases, HTML files themselves contain complex and powerful scripts and executables, an attack technique that is becoming more widely used than those involving externally hosted Javascript libraries.

For example, the following phishing attachment that looks like a Microsoft login has been around for several years and is highly deceptive. The attack is still in continuous and widespread use and still manages to trap many victims.

How to protect against malicious HTML attachments

To protect yourself from malicious HTML attachments, you should take a series of preventive measures:

1. Update Your Software Keep your operating system, web browser, and all installed software In the pop-up window, click the “…“, select the path to which you need to decompress, and the file will be saved directly under this path.

2. Use Robust Security Software

Employ reliable security software, such as antivirus software and firewalls, which can help you identify and block malicious attachments.

3. Be Cautious When Opening Unknown Attachments

If you’re uncertain about the source of an attachment or it looks suspicious, it’s best not to open it. Please send it to the company’s internal IT for confirmation.

4. Disable Automatic Loading of HTML Emails

Many email clients by default auto-load all content in HTML emails, including potentially hidden malicious code. You can disable this function in the settings of your email client.

5. Understand the Most Common Cyber Threats

Knowing what phishing attacks, malware, ransomware, etc., are, can help you identify potential threats.

6. Back-Up Your Data

Regularly back up your data to ensure that even if your system is attacked, you won’t lose important files.

7. Use Secure Email Services: ack-Up Your Data

Use email services with a good security record and strong spam filtering capabilities.

regularly back up your data to ensure that even if your system is attacked, you won’t lose important files.

8. IT Security Awareness Training

Regular IT security training and education for your staff can significantly reduce security issues caused by employee errors. Sinokap will provide customers with on-site and online IT security training to help end users subtly improve security awareness and ensure enterprise data security

These steps can help protect your system from the damage that malicious HTML attachments can cause.

Discover more from Sinokap

Subscribe now to keep reading and get access to the full archive.

Continue reading