Cybercriminals are increasingly using HTML attachments in phishing emails to evade detection and steal credentials, embedding malicious logic directly in attached files instead of placing suspicious links in the message body. The attachments commonly use JavaScript to redirect victims to fraudulent login pages or to display a complete phishing page locally inside the browser, making the email appear less obviously malicious to both users and some security controls.
Researchers found that attackers also obfuscate these attachments to hinder static analysis, including hiding phishing URLs, concealing entire scripts, and using deprecated JavaScript functions such as unescape() to decode and render phishing content at runtime. Kaspersky reported detecting nearly 2 million emails carrying malicious HTML attachments in the first four months of 2022, including 851,328 blocked in March alone, underscoring how effective and persistent the technique remains for credential-harvesting campaigns.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Kaspersky detected and blocked 851,328 emails with phishing HTML attachments in March 2022. This was highlighted as a peak month within the early-2022 activity described in the article.
The article states that January 2022 was the calmest month in the period, with 299,859 emails containing phishing HTML attachments detected by Kaspersky antispam solutions.
Kaspersky security solutions detected nearly 2 million emails containing malicious HTML attachments in the first four months of 2022. The article cites this as evidence that HTML attachments remained a widely used phishing technique.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.