Phishing attackers employed an HTML smuggling technique to deliver a malicious payload, as the attack chain started with a phishing email mimicking an American Express notification, leading to a series of redirects. The final redirect pointed to a Cloudflare R2 public bucket hosting an HTML file, which loaded an external JavaScript code that contained a Base64-encoded string that, when decoded, revealed the actual phishing page, demonstrating the effectiveness of HTML smuggling in obfuscating malicious content. Phishing mail impersonating American Express.
Source: GBHackers