May 8, 2023, 11:15 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Authored By Anuradha


McAfee Labs has recently observed a new wave of phishing attacks. In this wave, the attacker has been abusing server-parsed HTML (SHTML) files. The SHTML files are commonly associated with web servers redirecting users to malicious, credential-stealing websites or display phishing forms locally within the browser to harvest user-sensitive information. 


 SHTML Campaign in the field: 


 Figure 1. shows the geological distribution of McAfee clients who detect malicious SHTML files. 



Figure 1. McAfee Client Detection of SHTML 


 


Attackers …

abusing attack attacks blurred browser credential display files forms html information labs locally malicious mcafee phishing phishing attack phishing attacks sensitive information server servers stealing web websites

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)