Researchers documented a DanaBot loader campaign that used HTML smuggling to deliver malware through email, embedding a malicious ZIP archive directly inside an HTML attachment rather than downloading it from an external server. In the observed lure, Polish-language text told the recipient that the file could not be previewed and should be downloaded, after which the HTML generated a file named dokumentacja_28380.zip for the victim.
The delivery method relied on a data: URI containing a base64-encoded ZIP archive in the link itself, allowing the payload to be reconstructed locally in the browser and reducing visible network indicators. Separate technical analysis of HTML smuggling explains that the technique abuses standard browser features to assemble and save malicious content on the endpoint, helping attackers bypass some gateway inspection and URL-based defenses.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
G DATA described a DanaBot loader delivery technique in which a phishing email used HTML smuggling to drop a ZIP archive named "dokumentacja_28380.zip." The payload was embedded directly in a base64 data URI within the email's download link rather than fetched from an external URL.
Outflank published a blog post explaining the HTML smuggling technique. The reference provides the publication date but no additional event details in the supplied content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.