HTML Files Top the List as the Most Commonly Used Malicious Attachment

Stu Sjouwerman | Jun 29, 2023

HTML Files Top ListAs executables and scripts are unable to bypass security solutions as attachments, cybercriminals turn to HTML as a means of obfuscation and malicious execution.

According to analysis from security vendor Avanan, executables and Office documents as malicious attachments are almost non-existent – thanks to the solid efforts on the part of security companies and Microsoft. But cybercriminals are still succeeding in harvesting credentials as made evident by their use as the top threat action in data breaches, which makes HTML files a perfect tool. According to Avanan, 53% of malicious attachments today are HTML files.

5-29-23 Image

Source: Avanan

Beyond their ability to host links, JavaScript, embedded images, HTML entities, and customized CSS to escape detection, they also create a completely threat actor-controlled environment in which to impersonate legitimate websites to convince victims to provide their username and password. Additionally, by not needing to point the victim to a malicious website (that can be flagged as being suspicious by security solutions), there’s a better chance of a successful attack.

Those of us that are more technically-minded already know there’s no real reason an HTML file ever needs to be sent as an attachment, but users still are falling for this technique, making it necessary to educate them with Security Awareness Training on how these attacks work and how to identify them, reducing organizational risk.

Topics: Cybersecurity

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.