This new 'linkless' phishing scam is even tricking tech experts

(Image credit: wk1003mike / Shutterstock)

The antivirus firm Sophos has observed two new phishing campaigns in the wild that use a new trick to help them avoid detection.

Email phishing scams typically employ a three-stage process to get potential targets to give up their credentials which begins with an email that contains a URL they want users to click through. Clicking on this link will bring potential victims to a fake login page where their credentials are harvested and then sent to another site where the cybercriminals behind the campaign will use them to takeover user accounts.

However, these two new phishing campaigns, one of which Sophos received directly and one was reported by a reader, also use this same three-stage process but with a slight twist.

The cloned website in step two wasn't reached by clicking a link in an email. Instead, the fake website was attached to the email itself as an HTML attachment.

By attaching the URL of their phishing sites to emails, the cybercriminals behind these new campaigns are increasing the likelihood that a victim would open their fake web pages. This is because opening an attachment doesn't feel nearly as dangerous since it's not a document that could contain macros, a PowerShell file or an executable program.

Theoretically, opening an HTML attachment should simply open up the enclosed web page in the safety of a browser's sandbox just as if a victim had clicked on a link. However, by using an HTML attachment, users are unable to check out the link in advance to look for a fake or suspicious domain name and the URL in the address bar appears as if it were a local filename.

Sophos warned about the dangers of opening HTML attachments in a new blog post, saying:

“There are other reasons not to open HTML attachments, notably to do with JavaScript. For safety’s sake, script code inside HTML emails is stripped or blocked when any modern email reader displays the message. That’s a precaution that email software introduced decades ago when self-spreading script viruses such as Kakworm literally spread everywhere. Kakworm’s script code would activate and the virus would spread as soon as the email was displayed, without waiting for you to click any further. When you open an HTML attachment, however, it is no longer under the strict controls of your email client software, and any JavaScript inside the HTML will be allowed to run by default by your browser.”

To avoid falling victim to these new phishing campaigns, Sophos recommends that users avoid HTM or HTML attachments altogether, never log in to web pages that you arrived at from an email, turn on 2FA when possible, change passwords once you believe you've been phished and use a web filter.

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Google Pixel 8a in aloe green showing
Google Pixel 9a benchmark link teases the performance of the upcoming mid-ranger
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 17 (game #1148)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 17 (game #379)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 17 (game #645)
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over