Phishing Series 2026: HTML Smuggling Attachment Bypass of Email Gateway Filtering

This rule detects mass phishing campaigns by identifying HTML/HTM email attachments that contain embedded URLs. It monitors for a pattern where the same sender distributes these attachments to multiple recipients, a common behavior for HTML smuggling delivery vectors where malicious payloads are constructed client-side to bypass static email gateway inspection.