Activity timeline
T1027.006 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 3 reports, and 11 of the 11 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1027.006 HTML Smuggling is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of T1027 Obfuscated Files or Information. Threadlinqs maps 11 of 2623 tracked threats (0.4%) to it; by severity that is 2 critical, 7 high, 2 medium.
Threats that use T1027.006 most often also use T1566.001 Spearphishing Attachment (9 threats), T1204.002 Malicious File (8 threats), T1071.001 Web Protocols (6 threats), T1539 Steal Web Session Cookie (6 threats), T1566.002 Spearphishing Link (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
3 tracked threat actors appear in the threats that use T1027.006; the most frequent are Gamaredon (1), LockBit 5.0 (1), Qilin (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1027.006.
Data sources
Telemetry that can reveal T1027.006, per MITRE ATT&CK.
- File — File Creation
Threat actors using it
Tracked threats
11 tracked threats use T1027.006.
- ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and…high
- Fake Voicemail SVG Phishing Campaign Bypasses Email Filters via MIME Spoofinghigh
- Mirage2FA Phishing-as-a-Service Surge Hits 4,532 US and EU Organizations, Abusing Microsoft 365 Login Flowshigh
- DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smugglinghigh
- ASEC June 2026 Financial Sector Threat Roundup: Phishing-to-Infostealer Chains and Ransomware Dark Web Sales…medium
- Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…high
- HTML Phishing Attachment Uses "Comment Stuffing" to Evade AI-Based Detection (SharePoint/Teams Credential…medium
- Kali365/Octopi365 Device Code Phishing-as-a-Service Campaigncritical
- Mirage2FA Phishing Kit Targets Microsoft 365 via HTML Smuggling and MFA-Bypass Simulationhigh
- AccountDumpling — Vietnamese-Linked Facebook Business Hijacking Campaign Abusing Google AppSheet (~30,000…high
- CVE-2026-32202 — Windows Shell Protection Mechanism Failure: NTLM Authentication Coercion via Auto-Parsed…critical
Detection coverage
Threadlinqs maintains 28 detection rules mapped to T1027.006 (SPL 11, KQL 7, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1027 Obfuscated Files or Information — 1177 tracked threats at the technique level.