Email users have long thought of executable and .dll attachments as the main focus when it comes to cyberattacks, but there may be another type of malicious file that is also frequently used. According to findings from IT security firm Barracuda Networks, HTML attachments are used by hackers the most when it comes to cyberattacks, and 21% of all HTML attachments scanned by the company were found to be malicious.

“These attacks are difficult to detect because the HTML attachments themselves are not malicious,” wrote Olesia Klevchuk, senior product marketing manager for email security at Barracuda Networks. “The attackers do not include malware in the attachment itself, but instead use multiple redirects with Java script libraries hosted elsewhere.”
HTML attachments are commonly used in email communication. These are particularly common in system-generated email reports that users may receive on a regular basis. These messages include URL links to the actual report.
Why are HTML attachments used in attacks?
HTML attachments are more widely used because the attacks are harder to detect by both users and systems. In the example provided by Barracuda, the HTML attachment itself is not malicious, but it ultimately leads the user to a malicious website.
HTML attachments nearly double the speed of the next most common file type found to be malicious. See the other malicious file types below:
- Text (9%)
- XHTML (4%)
- Binary (0.3%)
- Scripts (0.08%)
- Rtf (0.04%)
- MS Office (0.03%)
- PDF (0.009%)
So what we learned is that HTML attachments are the most popular type of malicious file used by hackers, but how does this work?
Barracuda found that hackers have been embedding malicious HTML files into emails that users regularly receive , such as a link to a report. In reality, this is a phishing email with a malicious URL attached to it. Through this method, cybercriminals are no longer required to place links in the body of an email, which makes them easy to detect. The HTML method is much more difficult than previous attempts and can bypass both anti-spam and anti-virus policies at a higher rate.
When these are opened, the HTML uses a Java script to send the user to a third-party machine, asking the user to enter their personal credentials to log in or download a file that is malware. Also, this method does not require the hacker to create a fake website to carry out this attack, but instead can create a phishing form embedded in the attachment, sending phishing sites as attachments instead of links.

How to protect systems from malicious HTML attachments
Barracuda emphasizes three key tips to prevent these attacks:
- Make sure your email protection scans and blocks malicious HTML attachments
- Train your users to recognize and report potentially malicious HTML attachments
- If the malicious email gets through, have post delivery recovery tools ready
Information source: techrepublic.com
