A new phishing email campaign uses HTML attachments that abuse the Windows search protocolto push bulk files hosted on remote servers that deliver malware.
See also: Phishing attacks: Significant increase in the US and Europe

The Windows Search protocol is a Uniform Resource Identifier (URI) that allows applications to open Windows Explorer to perform searches using specific parameters.
While most Windows searches look at the local device index, it is also possible to force Windows Search to query shared files on remote hosts and use a custom title for the search window. Attackers can exploit this feature to share malicious files on remote servers, as first highlighted by Professor Dr. Martin Johns in a 2020 thesis.
In June 2022, security researchers devised a powerful attack chain that also exploited a Microsoft Office to launch searches directly from Word.
Trustwave SpiderLabs researchers now report that this technique is being actively used by malicious actors, who use HTML attachments to initiate Windows searches on attackers' servers .
See also: New phishing attack distributes More_eggs malware
Abuse of Windows Search
The recent attacks described in the Trustwave report begin with a malicious email message that carries an HTML attachment disguised as an invoice document placed in a small ZIP file. The ZIP helps to avoid security/AV scanners that may not analyze the files for malicious content.

The HTML file uses the tag <meta http-equiv= “refresh”> to cause the browser to automatically open a malicious URL when the HTML document is opened. If the meta refresh fails due to browser settings that prevent redirects or other reasons, an anchor tag provides a clickable link to the malicious URL, which acts as an alternative mechanism. This, however, requires action from the user.
In this case, the URL is intended for the Windows search protocol to search a remote host using the following parameters:
Query: Searches for items labeled “INVOICE”.
Crumb: Specifies the search scope, pointing to a malicious server via Cloudflare.
Display Name: Renames the search screen to “Downloads” to mimic a legitimate interface.
Location: Uses Cloudflare’s tunneling service to hide the server, making it appear legitimate by presenting remote resources as local files.
The search then retrieves the list of files from the remote server, displaying a single shortcut (LNK) file called invoice. If the victim clicks on the file, a script (BAT) hosted on the same server is triggered.
See also: New V3B phishing kit targets bank customers – Greece also in the crosshairs
Phishing emails are a widespread form of cyberattack, where attackers masquerade as trusted entities to trick recipients into revealing sensitive information. These emails often appear to come from trusted sources, such as banks, government agencies, or well-known companies, making it difficult for individuals to discern their fraudulent nature. Common tactics used in phishing emails include the inclusion of urgent messages, threats of account suspension, or promises of rewards. The ultimate goal is to trick the recipient into clicking on malicious links or downloading harmful attachments, leading to personal data theft, financial loss, or malware infiltration into the user’s system. Staying vigilant, verifying the authenticity of the sender, and employing strong cybersecurity measures are critical steps in defending against phishing attempts.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
