# T1027.006 HTML Smuggling

> As of 2026-10-05, T1027.006 (HTML Smuggling) appears in 11 tracked threats, first reported 2026-04-29 and most recently 2026-09-28, with linked actors including Gamaredon, LockBit 5.0, Qilin; it most often appears alongside T1566.001 (Spearphishing Attachment).

- **Tracked threats:** 11 (2 critical, 7 high, 2 medium)
- **First seen:** 2026-04-29
- **Last seen:** 2026-09-28
- **Threat actors:** 3
- **Detection rules:** 28 (counts only; Blue tier and above)

## Key facts

- **ID:** T1027.006
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1027
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1027/006/

## Activity timeline

T1027.006 first appeared in tracked threats on 2026-04-29 and was most recently reported on 2026-09-28. The busiest month was 2026-07 with 3 reports, and 11 of the 11 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1027.006 HTML Smuggling is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027). Threadlinqs maps 11 of 2623 tracked threats (0.4%) to it; by severity that is 2 critical, 7 high, 2 medium.

Threats that use T1027.006 most often also use [T1566.001 Spearphishing Attachment](https://intel.threadlinqs.com/technique/T1566.001) (9 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (8 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (6 threats), [T1539 Steal Web Session Cookie](https://intel.threadlinqs.com/technique/T1539) (6 threats), [T1566.002 Spearphishing Link](https://intel.threadlinqs.com/technique/T1566.002) (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

3 tracked threat actors appear in the threats that use T1027.006; the most frequent are [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) (1), [LockBit 5.0](https://intel.threadlinqs.com/actor/LockBit%205.0) (1), [Qilin](https://intel.threadlinqs.com/actor/Qilin) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1027.006.

- [M1048 Application Isolation and Sandboxing](https://attack.mitre.org/mitigations/M1048/)

## Data sources

Telemetry that can reveal T1027.006, per MITRE ATT&CK.

- File — File Creation

## Threat actors using it

- [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) — 1
- [LockBit 5.0](https://intel.threadlinqs.com/actor/LockBit%205.0) — 1
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 1

## Tracked threats

11 tracked threats use T1027.006.

- [ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and…](https://intel.threadlinqs.com/threat/TL-2026-2730) — high — 2026-09-28
- [Fake Voicemail SVG Phishing Campaign Bypasses Email Filters via MIME Spoofing](https://intel.threadlinqs.com/threat/TL-2026-2230) — high — 2026-08-30
- [Mirage2FA Phishing-as-a-Service Surge Hits 4,532 US and EU Organizations, Abusing Microsoft 365 Login Flows](https://intel.threadlinqs.com/threat/TL-2026-2140) — high — 2026-08-25
- [DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling](https://intel.threadlinqs.com/threat/TL-2026-2015) — high — 2026-08-14
- [ASEC June 2026 Financial Sector Threat Roundup: Phishing-to-Infostealer Chains and Ransomware Dark Web Sales…](https://intel.threadlinqs.com/threat/TL-2026-1597) — medium — 2026-07-21
- [Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…](https://intel.threadlinqs.com/threat/TL-2026-1210) — high — 2026-07-11
- [HTML Phishing Attachment Uses "Comment Stuffing" to Evade AI-Based Detection (SharePoint/Teams Credential…](https://intel.threadlinqs.com/threat/TL-2026-1168) — medium — 2026-07-10
- [Kali365/Octopi365 Device Code Phishing-as-a-Service Campaign](https://intel.threadlinqs.com/threat/TL-2026-0984) — critical — 2026-06-28
- [Mirage2FA Phishing Kit Targets Microsoft 365 via HTML Smuggling and MFA-Bypass Simulation](https://intel.threadlinqs.com/threat/TL-2026-0959) — high — 2026-06-27
- [AccountDumpling — Vietnamese-Linked Facebook Business Hijacking Campaign Abusing Google AppSheet (~30,000…](https://intel.threadlinqs.com/threat/TL-2026-0453) — high — 2026-05-04
- [CVE-2026-32202 — Windows Shell Protection Mechanism Failure: NTLM Authentication Coercion via Auto-Parsed…](https://intel.threadlinqs.com/threat/TL-2026-0435) — critical — 2026-04-29

## Related CVEs

CVEs referenced by the tracked threats that use T1027.006, most frequent first.

- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-21510](https://intel.threadlinqs.com/cve/CVE-2026-21510)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-32202](https://intel.threadlinqs.com/cve/CVE-2026-32202)

## Detection coverage

Threadlinqs maintains 28 detection rules mapped to T1027.006 (SPL 11, KQL 7, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.

28 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) — 1177 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1027.006
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
