Skip to main content
← Back to Demos
Script Injection intermediate · 15 min

HTML page assembling payload in browser and auto-downloading it

A new loader called OXLOADER is being distributed through malicious Google Ads, delivering the CastleStealer infostealer to users searching for legitimate software. HTML smuggling is the mechanism: the page's JavaScript builds the payload as a Blob entirely inside the browser, then triggers a download - so no malicious file ever crosses the network as such, and gateway filters see only a normal-looking web page (MITRE T1027.006). Once the victim opens the downloaded file, the infostealer harvests credentials and browser data. Deep CDR sanitizes the HTML by removing embedded scripts and re-encoding the page, so the browser never assembles the payload in the first place. The demo uses a benign Blob that would only invoke calc, making it safe to run.

Attack Technique

HTML smuggling

MITRE ATT&CK

T1027.006 ↗

Platforms

linuxwindows

File Types

.html

MetaDefender Capabilities

Deep CDR

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---