Advertisement
Top
image credit: Unsplash

Ongoing Campaign Uses HTML Smuggling for Malware Delivery

August 19, 2020

Referred to as Duri, the campaign started in early July and continues to date, attempting to evade network security solutions, including proxies and sandboxes, to deliver malicious code.

The employed technique, HTML smuggling, relies on HTML5/JavaScript for the download of files, and can be of two types: Data URLs are used for the download; or a JavaScript blob is created, and a specific MIME-type is used to download content.

Read More on Security Week