<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Behind the Surface Analysis Blog]]></title><description><![CDATA[Technical analysis of attack tools and methods I see. Also check out my YouTube channel: https://youtube.com/@behind_the_surface]]></description><link>https://www.behindthesurface.net</link><image><url>https://substackcdn.com/image/fetch/$s_!QSgJ!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c55a869-412f-4d0c-b22e-8a281c4fe91c_811x811.png</url><title>Behind the Surface Analysis Blog</title><link>https://www.behindthesurface.net</link></image><generator>Substack</generator><lastBuildDate>Sat, 02 May 2026 14:25:45 GMT</lastBuildDate><atom:link href="https://www.behindthesurface.net/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Travis Simcox]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[behindthesurface@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[behindthesurface@substack.com]]></itunes:email><itunes:name><![CDATA[Travis Simcox]]></itunes:name></itunes:owner><itunes:author><![CDATA[Travis Simcox]]></itunes:author><googleplay:owner><![CDATA[behindthesurface@substack.com]]></googleplay:owner><googleplay:email><![CDATA[behindthesurface@substack.com]]></googleplay:email><googleplay:author><![CDATA[Travis Simcox]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[How HTMLMIX Uses AI to Help Cybercriminals Evade Email Security Filters]]></title><description><![CDATA[Real threat actors are using AI-powered tools like HTMLMIX to bypass email filters at scale. Here's how the tool works and how to defend against it.]]></description><link>https://www.behindthesurface.net/p/how-htmlmix-uses-ai-to-help-cybercriminals</link><guid isPermaLink="false">https://www.behindthesurface.net/p/how-htmlmix-uses-ai-to-help-cybercriminals</guid><dc:creator><![CDATA[Travis Simcox]]></dc:creator><pubDate>Tue, 20 Jan 2026 14:22:42 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/c3f29608-3618-45d4-ac11-4670152e17c7_750x296.avif" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Originally published as a <a href="https://abnormal.ai/blog/ai-powered-phishing-tool-htmlmix">collaboration with Abnormal AI</a><br>Watch the related episode <a href="https://www.youtube.com/watch?v=FN0Rf0d8mXg">here</a><br><br>The cybersecurity industry has witnessed no shortage of breathless headlines about AI-powered cyberattacks. Most turned out to be proof-of-concept demonstrations or vaporware, exaggerated beyond recognition by vendors seeking attention. We&#8217;re cutting through the hype to examine a real AI tool actively used by real threat actors, with evidence drawn directly from underground forums and live campaigns.</p><p>This first installment focuses on phishing email generation&#8212;specifically, how threat actors are leveraging artificial intelligence to evade detection at scale.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.behindthesurface.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Behind the Surface Analysis Blog! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>From Spintax to AI: The Evolution of Email Obfuscation</h2><p>The concept of automated email variation isn&#8217;t new. Years ago, while investigating a Royal Ransomware campaign, I observed affiliates using a rudimentary spintax generator&#8212;a GUI tool adapted from the world of blackhat SEO. The operator would select non-critical words in their phishing template and provide alternative options. The tool would randomly replace these words in each outgoing message, creating sufficient variation to evade signature-based detection.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4Mq5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996bf433-3bbf-4d79-8e6b-a9fd7b339b92_1536x838.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4Mq5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996bf433-3bbf-4d79-8e6b-a9fd7b339b92_1536x838.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4Mq5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996bf433-3bbf-4d79-8e6b-a9fd7b339b92_1536x838.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4Mq5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996bf433-3bbf-4d79-8e6b-a9fd7b339b92_1536x838.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4Mq5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996bf433-3bbf-4d79-8e6b-a9fd7b339b92_1536x838.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4Mq5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996bf433-3bbf-4d79-8e6b-a9fd7b339b92_1536x838.jpeg" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/996bf433-3bbf-4d79-8e6b-a9fd7b339b92_1536x838.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HTMLMIX 1 Email Obfuscation Evolution&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HTMLMIX 1 Email Obfuscation Evolution" title="HTMLMIX 1 Email Obfuscation Evolution" srcset="https://substackcdn.com/image/fetch/$s_!4Mq5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996bf433-3bbf-4d79-8e6b-a9fd7b339b92_1536x838.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4Mq5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996bf433-3bbf-4d79-8e6b-a9fd7b339b92_1536x838.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4Mq5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996bf433-3bbf-4d79-8e6b-a9fd7b339b92_1536x838.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4Mq5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996bf433-3bbf-4d79-8e6b-a9fd7b339b92_1536x838.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The results were predictable: roughly half the emails read like plausible English, while the other half emerged as barely coherent word salad. Anyone who has spent significant time analyzing spam has undoubtedly encountered these spintax-generated messages, though many analysts may not have recognized them as such.</p><p>Spintax represented the floor, not the ceiling. Today, as generative AI reshapes how we create content online, the barrier to entry for sophisticated email obfuscation has collapsed. Modern threat actors use AI to generate variations in words, fonts, spacing, and coloring that appear nearly identical to the human eye but produce wildly different HTML representations&#8212;each one a unique fingerprint that evades pattern-matching filters.</p><p>More significantly, we&#8217;re witnessing a fundamental shift in the threat landscape: away from locally-run scripts and toward API-based Obfuscation-as-a-Service platforms. These services democratize advanced evasion techniques, placing enterprise-grade capabilities in the hands of relatively unsophisticated operators.</p><p>Enter HTMLMIX (sometimes stylized as HTM|MIX), a tool that exemplifies this new paradigm. What follows is a technical examination of this platform: its capabilities, its reputation among established threat actors, how it operates at scale, and what defenders need to know to counter the next wave of AI-obfuscated phishing.</p><h2>HTMLMIX&#8217;s Obfuscation Toolkit: From Basic HTML Tricks to AI-Powered Content</h2><p>To understand what makes HTMLMIX effective, let&#8217;s examine how it processes two common scenarios: a straightforward invoice scam and a Microsoft 365 credential harvesting attempt.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cFIK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd240dc3-0fdf-42fa-b255-d01d229efe23_1536x448.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cFIK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd240dc3-0fdf-42fa-b255-d01d229efe23_1536x448.png 424w, https://substackcdn.com/image/fetch/$s_!cFIK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd240dc3-0fdf-42fa-b255-d01d229efe23_1536x448.png 848w, https://substackcdn.com/image/fetch/$s_!cFIK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd240dc3-0fdf-42fa-b255-d01d229efe23_1536x448.png 1272w, https://substackcdn.com/image/fetch/$s_!cFIK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd240dc3-0fdf-42fa-b255-d01d229efe23_1536x448.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cFIK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd240dc3-0fdf-42fa-b255-d01d229efe23_1536x448.png" width="1456" height="425" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bd240dc3-0fdf-42fa-b255-d01d229efe23_1536x448.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:425,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HTMLMIX 2 Invoice Fraud Email&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HTMLMIX 2 Invoice Fraud Email" title="HTMLMIX 2 Invoice Fraud Email" srcset="https://substackcdn.com/image/fetch/$s_!cFIK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd240dc3-0fdf-42fa-b255-d01d229efe23_1536x448.png 424w, https://substackcdn.com/image/fetch/$s_!cFIK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd240dc3-0fdf-42fa-b255-d01d229efe23_1536x448.png 848w, https://substackcdn.com/image/fetch/$s_!cFIK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd240dc3-0fdf-42fa-b255-d01d229efe23_1536x448.png 1272w, https://substackcdn.com/image/fetch/$s_!cFIK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd240dc3-0fdf-42fa-b255-d01d229efe23_1536x448.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Example 1: Invoice Fraud</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!m9Oh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38422060-b571-40f0-a6ab-21d3e2388114_1536x1410.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!m9Oh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38422060-b571-40f0-a6ab-21d3e2388114_1536x1410.jpeg 424w, https://substackcdn.com/image/fetch/$s_!m9Oh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38422060-b571-40f0-a6ab-21d3e2388114_1536x1410.jpeg 848w, https://substackcdn.com/image/fetch/$s_!m9Oh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38422060-b571-40f0-a6ab-21d3e2388114_1536x1410.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!m9Oh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38422060-b571-40f0-a6ab-21d3e2388114_1536x1410.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!m9Oh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38422060-b571-40f0-a6ab-21d3e2388114_1536x1410.jpeg" width="1456" height="1337" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/38422060-b571-40f0-a6ab-21d3e2388114_1536x1410.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1337,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HTMLMIX 3 Microsoft 365 Email&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HTMLMIX 3 Microsoft 365 Email" title="HTMLMIX 3 Microsoft 365 Email" srcset="https://substackcdn.com/image/fetch/$s_!m9Oh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38422060-b571-40f0-a6ab-21d3e2388114_1536x1410.jpeg 424w, https://substackcdn.com/image/fetch/$s_!m9Oh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38422060-b571-40f0-a6ab-21d3e2388114_1536x1410.jpeg 848w, https://substackcdn.com/image/fetch/$s_!m9Oh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38422060-b571-40f0-a6ab-21d3e2388114_1536x1410.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!m9Oh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38422060-b571-40f0-a6ab-21d3e2388114_1536x1410.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Example 2: Microsoft 365 Credential Phishing</em></p><p>Now let&#8217;s examine what HTMLMIX does to these templates.</p><h3>Traditional HTML Obfuscation Techniques</h3><p>HTMLMIX automates several HTML manipulation tactics that have existed for years but previously required manual implementation:</p><ul><li><p><strong>Trusted domain injection</strong>: Sprinkling links to legitimate sites (Google, Microsoft, major news outlets) throughout the email to improve sender reputation scores</p></li><li><p><strong>Invisible character insertion</strong>: Adding zero-width spaces, non-breaking spaces, and other invisible Unicode characters that alter the text&#8217;s digital signature without affecting visual appearance</p></li><li><p><strong>HTML structure mangling</strong>: Inserting unnecessary tags, randomizing font variations, introducing subtle color changes, swapping semantically equivalent tags, and renaming CSS classes&#8212;all producing HTML that looks identical when rendered but appears completely different to signature-based detection systems</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZObE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e77e7b-10db-45c9-8f95-e733fbd26e34_1536x607.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZObE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e77e7b-10db-45c9-8f95-e733fbd26e34_1536x607.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZObE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e77e7b-10db-45c9-8f95-e733fbd26e34_1536x607.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZObE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e77e7b-10db-45c9-8f95-e733fbd26e34_1536x607.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZObE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e77e7b-10db-45c9-8f95-e733fbd26e34_1536x607.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZObE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e77e7b-10db-45c9-8f95-e733fbd26e34_1536x607.jpeg" width="1456" height="575" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d7e77e7b-10db-45c9-8f95-e733fbd26e34_1536x607.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:575,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HTMLMIX 4 AI Edited Invoice Fraud Email&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HTMLMIX 4 AI Edited Invoice Fraud Email" title="HTMLMIX 4 AI Edited Invoice Fraud Email" srcset="https://substackcdn.com/image/fetch/$s_!ZObE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e77e7b-10db-45c9-8f95-e733fbd26e34_1536x607.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZObE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e77e7b-10db-45c9-8f95-e733fbd26e34_1536x607.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZObE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e77e7b-10db-45c9-8f95-e733fbd26e34_1536x607.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZObE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e77e7b-10db-45c9-8f95-e733fbd26e34_1536x607.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>When we apply these techniques to our invoice example, the visual output remains nearly identical&#8212;perhaps some minor whitespace differences if you scrutinize closely. However, the underlying HTML expands from a few hundred bytes to over 21KB of obfuscated code, with each instance unique enough to evade pattern matching.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HRWr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa30942d-a23c-4dad-9ba8-8cd42a4f2731_1536x509.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HRWr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa30942d-a23c-4dad-9ba8-8cd42a4f2731_1536x509.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HRWr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa30942d-a23c-4dad-9ba8-8cd42a4f2731_1536x509.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HRWr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa30942d-a23c-4dad-9ba8-8cd42a4f2731_1536x509.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HRWr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa30942d-a23c-4dad-9ba8-8cd42a4f2731_1536x509.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HRWr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa30942d-a23c-4dad-9ba8-8cd42a4f2731_1536x509.jpeg" width="1456" height="482" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aa30942d-a23c-4dad-9ba8-8cd42a4f2731_1536x509.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:482,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HTMLMIX 5 AI Edited Invoice Fraud Email HTML&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HTMLMIX 5 AI Edited Invoice Fraud Email HTML" title="HTMLMIX 5 AI Edited Invoice Fraud Email HTML" srcset="https://substackcdn.com/image/fetch/$s_!HRWr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa30942d-a23c-4dad-9ba8-8cd42a4f2731_1536x509.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HRWr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa30942d-a23c-4dad-9ba8-8cd42a4f2731_1536x509.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HRWr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa30942d-a23c-4dad-9ba8-8cd42a4f2731_1536x509.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HRWr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa30942d-a23c-4dad-9ba8-8cd42a4f2731_1536x509.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Interestingly, some of these older obfuscation tactics now actually increase detection rates. Modern machine learning-based filters have been trained to recognize the signatures of excessive HTML manipulation, meaning blind application of every available technique can backfire. HTMLMIX&#8217;s &#8220;auto mode&#8221; attempts to balance evasion with plausibility, though with mixed results.</p><h3>Algorithmic Obfuscation Methods</h3><p>Beyond familiar HTML tricks, HTMLMIX incorporates more sophisticated algorithmic techniques:</p><ul><li><p><strong>Image pixelation as HTML</strong>: Converting images into HTML structures composed of colored div blocks, creating visually identical images from completely different code</p></li><li><p><strong>Tabular randomization</strong>: Fragmenting text into table cells with randomized word counts per cell, breaking up the linguistic patterns that content-based filters analyze</p></li><li><p><strong>CSS class extraction</strong>: Programmatically extracting inline styles, generating unique CSS class names, and applying these classes to elements&#8212;creating functionally identical styling from technically unique code</p></li></ul><p>These techniques represent an evolution beyond simple find-and-replace operations. They algorithmically restructure the email&#8217;s technical composition while preserving its visual and functional presentation.</p><h3>AI-Powered Features</h3><p>Where HTMLMIX truly distinguishes itself is in its AI integration. The platform offers four AI-powered capabilities:</p><p><strong>1. Regional Trending Words</strong></p><p>The tool can inject trending terms from selected geographic regions, potentially improving deliverability by making emails appear more current and contextually relevant.</p><p><strong>2. AI-Generated Synonyms</strong></p><p>This feature tackles the same problem as spintax but with dramatically improved results. We tested it on our invoice example with a creativity setting of 0.6 (on a scale from conservative to creative).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pSqW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c693d9-a524-4453-9705-3686fc2967aa_1536x601.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pSqW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c693d9-a524-4453-9705-3686fc2967aa_1536x601.jpeg 424w, https://substackcdn.com/image/fetch/$s_!pSqW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c693d9-a524-4453-9705-3686fc2967aa_1536x601.jpeg 848w, https://substackcdn.com/image/fetch/$s_!pSqW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c693d9-a524-4453-9705-3686fc2967aa_1536x601.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!pSqW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c693d9-a524-4453-9705-3686fc2967aa_1536x601.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pSqW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c693d9-a524-4453-9705-3686fc2967aa_1536x601.jpeg" width="1456" height="570" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e5c693d9-a524-4453-9705-3686fc2967aa_1536x601.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:570,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HTMLMIX 6 AI Generated Synonyms&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HTMLMIX 6 AI Generated Synonyms" title="HTMLMIX 6 AI Generated Synonyms" srcset="https://substackcdn.com/image/fetch/$s_!pSqW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c693d9-a524-4453-9705-3686fc2967aa_1536x601.jpeg 424w, https://substackcdn.com/image/fetch/$s_!pSqW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c693d9-a524-4453-9705-3686fc2967aa_1536x601.jpeg 848w, https://substackcdn.com/image/fetch/$s_!pSqW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c693d9-a524-4453-9705-3686fc2967aa_1536x601.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!pSqW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c693d9-a524-4453-9705-3686fc2967aa_1536x601.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Here are three variations it generated:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z9fc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22182823-ee15-4577-b138-63400b530ae5_1536x672.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z9fc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22182823-ee15-4577-b138-63400b530ae5_1536x672.png 424w, https://substackcdn.com/image/fetch/$s_!Z9fc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22182823-ee15-4577-b138-63400b530ae5_1536x672.png 848w, https://substackcdn.com/image/fetch/$s_!Z9fc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22182823-ee15-4577-b138-63400b530ae5_1536x672.png 1272w, https://substackcdn.com/image/fetch/$s_!Z9fc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22182823-ee15-4577-b138-63400b530ae5_1536x672.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z9fc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22182823-ee15-4577-b138-63400b530ae5_1536x672.png" width="1456" height="637" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22182823-ee15-4577-b138-63400b530ae5_1536x672.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:637,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HTMLMIX 7 Invoice Fraud Synonym Outputs&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HTMLMIX 7 Invoice Fraud Synonym Outputs" title="HTMLMIX 7 Invoice Fraud Synonym Outputs" srcset="https://substackcdn.com/image/fetch/$s_!Z9fc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22182823-ee15-4577-b138-63400b530ae5_1536x672.png 424w, https://substackcdn.com/image/fetch/$s_!Z9fc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22182823-ee15-4577-b138-63400b530ae5_1536x672.png 848w, https://substackcdn.com/image/fetch/$s_!Z9fc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22182823-ee15-4577-b138-63400b530ae5_1536x672.png 1272w, https://substackcdn.com/image/fetch/$s_!Z9fc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22182823-ee15-4577-b138-63400b530ae5_1536x672.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The improvement over spintax is substantial. Each version forms coherent, realistic sentences rather than word salad. The tone shifts slightly between variations&#8212;a careful reader might detect the inconsistency&#8212;but casual recipients would likely find nothing suspicious about any individual message.</p><p><strong>3. AI-Generated Preview Text</strong></p><p>The tool can generate varied preview text (the snippet visible in email clients before opening), ensuring that even this metadata differs across messages.</p><p><strong>4. Automated Email Thread Fabrication</strong></p><p>Perhaps the most ambitious AI feature, added to HTMLMIX in October 2025, attempts to generate realistic email conversation chains. In business email compromise (BEC) attacks, sophisticated threat actors often hijack legitimate email threads, then inject fraudulent payment requests. We also observe completely fabricated threads, though these typically look obviously fake.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N5NS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb4510b5-9b30-4333-8906-7cb8afb8f1f0_1536x751.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N5NS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb4510b5-9b30-4333-8906-7cb8afb8f1f0_1536x751.jpeg 424w, https://substackcdn.com/image/fetch/$s_!N5NS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb4510b5-9b30-4333-8906-7cb8afb8f1f0_1536x751.jpeg 848w, https://substackcdn.com/image/fetch/$s_!N5NS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb4510b5-9b30-4333-8906-7cb8afb8f1f0_1536x751.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!N5NS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb4510b5-9b30-4333-8906-7cb8afb8f1f0_1536x751.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N5NS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb4510b5-9b30-4333-8906-7cb8afb8f1f0_1536x751.jpeg" width="1456" height="712" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/db4510b5-9b30-4333-8906-7cb8afb8f1f0_1536x751.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:712,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HTMLMIX 10 Automated Fake Thread Interface&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HTMLMIX 10 Automated Fake Thread Interface" title="HTMLMIX 10 Automated Fake Thread Interface" srcset="https://substackcdn.com/image/fetch/$s_!N5NS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb4510b5-9b30-4333-8906-7cb8afb8f1f0_1536x751.jpeg 424w, https://substackcdn.com/image/fetch/$s_!N5NS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb4510b5-9b30-4333-8906-7cb8afb8f1f0_1536x751.jpeg 848w, https://substackcdn.com/image/fetch/$s_!N5NS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb4510b5-9b30-4333-8906-7cb8afb8f1f0_1536x751.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!N5NS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb4510b5-9b30-4333-8906-7cb8afb8f1f0_1536x751.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Testing this feature on our invoice example produced mixed results. The generated conversation flow made logical sense&#8212;emails about confirming an invoice, following up on payment, and discussing timeline concerns.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bZ1V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F114f4207-c4b1-4d11-9a14-1bc93951c43b_1536x436.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bZ1V!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F114f4207-c4b1-4d11-9a14-1bc93951c43b_1536x436.jpeg 424w, https://substackcdn.com/image/fetch/$s_!bZ1V!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F114f4207-c4b1-4d11-9a14-1bc93951c43b_1536x436.jpeg 848w, https://substackcdn.com/image/fetch/$s_!bZ1V!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F114f4207-c4b1-4d11-9a14-1bc93951c43b_1536x436.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!bZ1V!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F114f4207-c4b1-4d11-9a14-1bc93951c43b_1536x436.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bZ1V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F114f4207-c4b1-4d11-9a14-1bc93951c43b_1536x436.jpeg" width="1456" height="413" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/114f4207-c4b1-4d11-9a14-1bc93951c43b_1536x436.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:413,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HTMLMIX 11 Automated Fake Thread Output 1&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HTMLMIX 11 Automated Fake Thread Output 1" title="HTMLMIX 11 Automated Fake Thread Output 1" srcset="https://substackcdn.com/image/fetch/$s_!bZ1V!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F114f4207-c4b1-4d11-9a14-1bc93951c43b_1536x436.jpeg 424w, https://substackcdn.com/image/fetch/$s_!bZ1V!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F114f4207-c4b1-4d11-9a14-1bc93951c43b_1536x436.jpeg 848w, https://substackcdn.com/image/fetch/$s_!bZ1V!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F114f4207-c4b1-4d11-9a14-1bc93951c43b_1536x436.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!bZ1V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F114f4207-c4b1-4d11-9a14-1bc93951c43b_1536x436.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>However, all the participants used personal email addresses (@gmail.com, @icloud.com), which should immediately raise red flags in a B2B payment context.</p><p>When we tested the feature on the Microsoft 365 phishing email, it generated a completely unrelated conversation thread about quarterly sales reports, demonstrating the AI&#8217;s current limitations in maintaining contextual relevance.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7THj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7e29522-420f-4611-b213-2dff83d52e8f_1536x545.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7THj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7e29522-420f-4611-b213-2dff83d52e8f_1536x545.jpeg 424w, https://substackcdn.com/image/fetch/$s_!7THj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7e29522-420f-4611-b213-2dff83d52e8f_1536x545.jpeg 848w, https://substackcdn.com/image/fetch/$s_!7THj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7e29522-420f-4611-b213-2dff83d52e8f_1536x545.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!7THj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7e29522-420f-4611-b213-2dff83d52e8f_1536x545.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7THj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7e29522-420f-4611-b213-2dff83d52e8f_1536x545.jpeg" width="1456" height="517" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b7e29522-420f-4611-b213-2dff83d52e8f_1536x545.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:517,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HTMLMIX 12 Automated Fake Thread Output 2&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HTMLMIX 12 Automated Fake Thread Output 2" title="HTMLMIX 12 Automated Fake Thread Output 2" srcset="https://substackcdn.com/image/fetch/$s_!7THj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7e29522-420f-4611-b213-2dff83d52e8f_1536x545.jpeg 424w, https://substackcdn.com/image/fetch/$s_!7THj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7e29522-420f-4611-b213-2dff83d52e8f_1536x545.jpeg 848w, https://substackcdn.com/image/fetch/$s_!7THj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7e29522-420f-4611-b213-2dff83d52e8f_1536x545.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!7THj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7e29522-420f-4611-b213-2dff83d52e8f_1536x545.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Real-World Output: Before and After Obfuscation</h3><p>To see these techniques working in concert, we processed a basic phishing template through HTMLMIX&#8217;s auto mode, which applies a balanced selection of obfuscation techniques.</p><p>The &#8220;before&#8221; shows clean, minimal HTML&#8212;a simple email alert about a Google Workspace storage limit with a header, body text, and call-to-action button. Standard structure, straightforward code.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4ASd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f50476-db7c-4781-9a31-263a52360cfb_1536x1003.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4ASd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f50476-db7c-4781-9a31-263a52360cfb_1536x1003.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4ASd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f50476-db7c-4781-9a31-263a52360cfb_1536x1003.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4ASd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f50476-db7c-4781-9a31-263a52360cfb_1536x1003.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4ASd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f50476-db7c-4781-9a31-263a52360cfb_1536x1003.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4ASd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f50476-db7c-4781-9a31-263a52360cfb_1536x1003.jpeg" width="1456" height="951" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b0f50476-db7c-4781-9a31-263a52360cfb_1536x1003.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:951,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HTMLMIX 13 HTML Before Obfuscation&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HTMLMIX 13 HTML Before Obfuscation" title="HTMLMIX 13 HTML Before Obfuscation" srcset="https://substackcdn.com/image/fetch/$s_!4ASd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f50476-db7c-4781-9a31-263a52360cfb_1536x1003.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4ASd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f50476-db7c-4781-9a31-263a52360cfb_1536x1003.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4ASd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f50476-db7c-4781-9a31-263a52360cfb_1536x1003.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4ASd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0f50476-db7c-4781-9a31-263a52360cfb_1536x1003.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The &#8220;after&#8221; reveals what modern obfuscation looks like: the HTML has been shredded into fragments, restructured with nested divs and spans, injected with randomized CSS classes, and padded with invisible characters. The visual presentation remains virtually identical, but the underlying code has been transformed into something unrecognizable to signature-based detection systems.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Nu_2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4763adff-23e2-4635-86e3-681127b3c29d_1536x847.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Nu_2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4763adff-23e2-4635-86e3-681127b3c29d_1536x847.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Nu_2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4763adff-23e2-4635-86e3-681127b3c29d_1536x847.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Nu_2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4763adff-23e2-4635-86e3-681127b3c29d_1536x847.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Nu_2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4763adff-23e2-4635-86e3-681127b3c29d_1536x847.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Nu_2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4763adff-23e2-4635-86e3-681127b3c29d_1536x847.jpeg" width="1456" height="803" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4763adff-23e2-4635-86e3-681127b3c29d_1536x847.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:803,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HTMLMIX 14 HTML After Obfuscation&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HTMLMIX 14 HTML After Obfuscation" title="HTMLMIX 14 HTML After Obfuscation" srcset="https://substackcdn.com/image/fetch/$s_!Nu_2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4763adff-23e2-4635-86e3-681127b3c29d_1536x847.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Nu_2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4763adff-23e2-4635-86e3-681127b3c29d_1536x847.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Nu_2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4763adff-23e2-4635-86e3-681127b3c29d_1536x847.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Nu_2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4763adff-23e2-4635-86e3-681127b3c29d_1536x847.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This transformation happens in seconds via API, enabling threat actors to generate thousands of unique variants from a single template.</p><h2>Masking Malicious Links with Trusted Domains</h2><p>Obfuscating email content addresses only half the detection challenge. Attackers must also obscure the destinations of their links, since URL reputation checking remains one of the most effective anti-phishing controls.</p><p>HTMLMIX offers an optional upsell called &#8220;Trust Redirects&#8221; that leverages cloud infrastructure from trusted providers. The concept is straightforward: a link pointing to an Amazon S3 bucket or Microsoft Azure endpoint is far less likely to be blocked than a link to a newly-registered suspicious domain.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0dWV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e81951-22af-4caf-b811-38b54d3aed6e_1536x1319.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0dWV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e81951-22af-4caf-b811-38b54d3aed6e_1536x1319.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0dWV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e81951-22af-4caf-b811-38b54d3aed6e_1536x1319.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0dWV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e81951-22af-4caf-b811-38b54d3aed6e_1536x1319.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0dWV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e81951-22af-4caf-b811-38b54d3aed6e_1536x1319.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0dWV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e81951-22af-4caf-b811-38b54d3aed6e_1536x1319.jpeg" width="1456" height="1250" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/30e81951-22af-4caf-b811-38b54d3aed6e_1536x1319.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1250,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HTMLMIX 15 AWS Trust Redirects Interface&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HTMLMIX 15 AWS Trust Redirects Interface" title="HTMLMIX 15 AWS Trust Redirects Interface" srcset="https://substackcdn.com/image/fetch/$s_!0dWV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e81951-22af-4caf-b811-38b54d3aed6e_1536x1319.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0dWV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e81951-22af-4caf-b811-38b54d3aed6e_1536x1319.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0dWV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e81951-22af-4caf-b811-38b54d3aed6e_1536x1319.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0dWV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30e81951-22af-4caf-b811-38b54d3aed6e_1536x1319.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The service charges $20 per redirect, with the first test redirect free. For an additional fee, operators can purchase a &#8220;Personal Server&#8221; that increases their balance to $200+ and adds AWS keys for $10 per redirect instead of $20, lowering the per-campaign cost for high-volume operators.</p><p>The interface allows attackers to specify the destination URL, customize the page title (e.g., &#8220;Loading your Behind the Surface account&#8221;), choose the URL format (virtual-hosted vs. path-based), select parameter formatting (query vs. hash), and optionally append the .html extension.</p><p>Of course, this approach involves inherent tradeoffs. Amazon and Microsoft actively respond to abuse reports, meaning these redirects have limited lifespans&#8212;hours or days rather than weeks. But for time-sensitive campaigns targeting specific organizations, the temporary legitimacy can be worth the cost. The attacker simply needs the link to survive long enough for targets to click, not indefinitely.</p><h2>Why Threat Actors Love HTMLMIX</h2><p>Like many dark web services, HTMLMIX wraps itself in disclaimers about &#8220;legitimate,&#8221; &#8220;research,&#8221; and &#8220;educational&#8221; purposes. The interface prominently displays warnings that users are &#8220;solely responsible&#8221; for ensuring compliance with applicable laws and that the service &#8220;categorically forbids&#8221; the use of the platform for illegal purposes, including fraud, malware distribution, and spam.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yVSu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ba71f7-ef12-4524-af23-92ce4e286036_1536x170.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yVSu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ba71f7-ef12-4524-af23-92ce4e286036_1536x170.jpeg 424w, https://substackcdn.com/image/fetch/$s_!yVSu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ba71f7-ef12-4524-af23-92ce4e286036_1536x170.jpeg 848w, https://substackcdn.com/image/fetch/$s_!yVSu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ba71f7-ef12-4524-af23-92ce4e286036_1536x170.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!yVSu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ba71f7-ef12-4524-af23-92ce4e286036_1536x170.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yVSu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ba71f7-ef12-4524-af23-92ce4e286036_1536x170.jpeg" width="1456" height="161" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/95ba71f7-ef12-4524-af23-92ce4e286036_1536x170.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:161,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HTMLMIX 16 Disclaimer 1&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HTMLMIX 16 Disclaimer 1" title="HTMLMIX 16 Disclaimer 1" srcset="https://substackcdn.com/image/fetch/$s_!yVSu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ba71f7-ef12-4524-af23-92ce4e286036_1536x170.jpeg 424w, https://substackcdn.com/image/fetch/$s_!yVSu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ba71f7-ef12-4524-af23-92ce4e286036_1536x170.jpeg 848w, https://substackcdn.com/image/fetch/$s_!yVSu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ba71f7-ef12-4524-af23-92ce4e286036_1536x170.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!yVSu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ba71f7-ef12-4524-af23-92ce4e286036_1536x170.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>These disclaimers are, of course, meaningless. HTMLMIX is exclusively advertised on underground forums and can only be purchased using cryptocurrency&#8212;operational security measures that belie any pretense of legitimate use.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SE-l!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4822d580-72ca-4c65-a8a0-5488e15b4c43_1536x222.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SE-l!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4822d580-72ca-4c65-a8a0-5488e15b4c43_1536x222.jpeg 424w, https://substackcdn.com/image/fetch/$s_!SE-l!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4822d580-72ca-4c65-a8a0-5488e15b4c43_1536x222.jpeg 848w, https://substackcdn.com/image/fetch/$s_!SE-l!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4822d580-72ca-4c65-a8a0-5488e15b4c43_1536x222.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!SE-l!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4822d580-72ca-4c65-a8a0-5488e15b4c43_1536x222.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SE-l!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4822d580-72ca-4c65-a8a0-5488e15b4c43_1536x222.jpeg" width="1456" height="210" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4822d580-72ca-4c65-a8a0-5488e15b4c43_1536x222.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:210,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HTMLMIX 17 Disclaimer 2&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HTMLMIX 17 Disclaimer 2" title="HTMLMIX 17 Disclaimer 2" srcset="https://substackcdn.com/image/fetch/$s_!SE-l!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4822d580-72ca-4c65-a8a0-5488e15b4c43_1536x222.jpeg 424w, https://substackcdn.com/image/fetch/$s_!SE-l!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4822d580-72ca-4c65-a8a0-5488e15b4c43_1536x222.jpeg 848w, https://substackcdn.com/image/fetch/$s_!SE-l!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4822d580-72ca-4c65-a8a0-5488e15b4c43_1536x222.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!SE-l!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4822d580-72ca-4c65-a8a0-5488e15b4c43_1536x222.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>What reveals the service&#8217;s true purpose is the enthusiastic feedback from established threat actors in underground communities.</p><p>One endorsement comes from a moderator of XSS, a top-tier hacking forum, who is recognized as a filter bypass expert with activity dating back to 2012. When another user requests advice on phishing obfuscation, he replies simply: &#8220;There&#8217;s a service called htmlmix that&#8217;s way ahead in this area.&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wJjz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe72b7a88-50a8-4a96-a725-791c4cf1c96e_1536x180.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wJjz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe72b7a88-50a8-4a96-a725-791c4cf1c96e_1536x180.jpeg 424w, https://substackcdn.com/image/fetch/$s_!wJjz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe72b7a88-50a8-4a96-a725-791c4cf1c96e_1536x180.jpeg 848w, https://substackcdn.com/image/fetch/$s_!wJjz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe72b7a88-50a8-4a96-a725-791c4cf1c96e_1536x180.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!wJjz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe72b7a88-50a8-4a96-a725-791c4cf1c96e_1536x180.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wJjz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe72b7a88-50a8-4a96-a725-791c4cf1c96e_1536x180.jpeg" width="1456" height="171" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e72b7a88-50a8-4a96-a725-791c4cf1c96e_1536x180.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:171,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HTMLMIX 18 Feedback 1&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HTMLMIX 18 Feedback 1" title="HTMLMIX 18 Feedback 1" srcset="https://substackcdn.com/image/fetch/$s_!wJjz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe72b7a88-50a8-4a96-a725-791c4cf1c96e_1536x180.jpeg 424w, https://substackcdn.com/image/fetch/$s_!wJjz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe72b7a88-50a8-4a96-a725-791c4cf1c96e_1536x180.jpeg 848w, https://substackcdn.com/image/fetch/$s_!wJjz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe72b7a88-50a8-4a96-a725-791c4cf1c96e_1536x180.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!wJjz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe72b7a88-50a8-4a96-a725-791c4cf1c96e_1536x180.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Another testimonial comes from an established vendor on multiple top-tier forums:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yp2M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04fd8054-6b9a-40df-a597-92b2af37b1e1_1536x311.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yp2M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04fd8054-6b9a-40df-a597-92b2af37b1e1_1536x311.png 424w, https://substackcdn.com/image/fetch/$s_!yp2M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04fd8054-6b9a-40df-a597-92b2af37b1e1_1536x311.png 848w, https://substackcdn.com/image/fetch/$s_!yp2M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04fd8054-6b9a-40df-a597-92b2af37b1e1_1536x311.png 1272w, https://substackcdn.com/image/fetch/$s_!yp2M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04fd8054-6b9a-40df-a597-92b2af37b1e1_1536x311.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yp2M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04fd8054-6b9a-40df-a597-92b2af37b1e1_1536x311.png" width="1456" height="295" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/04fd8054-6b9a-40df-a597-92b2af37b1e1_1536x311.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:295,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HTMLMIX 19 Feedback 2&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HTMLMIX 19 Feedback 2" title="HTMLMIX 19 Feedback 2" srcset="https://substackcdn.com/image/fetch/$s_!yp2M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04fd8054-6b9a-40df-a597-92b2af37b1e1_1536x311.png 424w, https://substackcdn.com/image/fetch/$s_!yp2M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04fd8054-6b9a-40df-a597-92b2af37b1e1_1536x311.png 848w, https://substackcdn.com/image/fetch/$s_!yp2M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04fd8054-6b9a-40df-a597-92b2af37b1e1_1536x311.png 1272w, https://substackcdn.com/image/fetch/$s_!yp2M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04fd8054-6b9a-40df-a597-92b2af37b1e1_1536x311.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The pattern continues across multiple underground communities. Lesser-known operators echo similar sentiments:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QpK7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e626d13-f9d1-4a0e-81b1-3b3cc1c49d36_1536x750.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QpK7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e626d13-f9d1-4a0e-81b1-3b3cc1c49d36_1536x750.png 424w, https://substackcdn.com/image/fetch/$s_!QpK7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e626d13-f9d1-4a0e-81b1-3b3cc1c49d36_1536x750.png 848w, https://substackcdn.com/image/fetch/$s_!QpK7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e626d13-f9d1-4a0e-81b1-3b3cc1c49d36_1536x750.png 1272w, https://substackcdn.com/image/fetch/$s_!QpK7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e626d13-f9d1-4a0e-81b1-3b3cc1c49d36_1536x750.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QpK7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e626d13-f9d1-4a0e-81b1-3b3cc1c49d36_1536x750.png" width="1456" height="711" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1e626d13-f9d1-4a0e-81b1-3b3cc1c49d36_1536x750.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:711,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HTMLMIX 20 Feedback 3&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HTMLMIX 20 Feedback 3" title="HTMLMIX 20 Feedback 3" srcset="https://substackcdn.com/image/fetch/$s_!QpK7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e626d13-f9d1-4a0e-81b1-3b3cc1c49d36_1536x750.png 424w, https://substackcdn.com/image/fetch/$s_!QpK7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e626d13-f9d1-4a0e-81b1-3b3cc1c49d36_1536x750.png 848w, https://substackcdn.com/image/fetch/$s_!QpK7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e626d13-f9d1-4a0e-81b1-3b3cc1c49d36_1536x750.png 1272w, https://substackcdn.com/image/fetch/$s_!QpK7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e626d13-f9d1-4a0e-81b1-3b3cc1c49d36_1536x750.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This isn&#8217;t theoretical threat intelligence. These are real operators, some moving hundreds of thousands of phishing emails weekly, providing unprompted testimonials about a tool that measurably improves their success rates.</p><h2>From GUI to API: Scaling Phishing Campaigns</h2><p>The threat posed by HTMLMIX extends beyond its technical capabilities. What makes it particularly dangerous is its scalability.</p><p>Individual phishers might use the web interface to manually process templates, but sophisticated operators integrate HTMLMIX directly into their attack infrastructure via API. This transforms obfuscation from a manual bottleneck into an automated pipeline component.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jh9D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18f78c1-4733-43a3-906f-e5ecd1491547_1536x737.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jh9D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18f78c1-4733-43a3-906f-e5ecd1491547_1536x737.jpeg 424w, https://substackcdn.com/image/fetch/$s_!jh9D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18f78c1-4733-43a3-906f-e5ecd1491547_1536x737.jpeg 848w, https://substackcdn.com/image/fetch/$s_!jh9D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18f78c1-4733-43a3-906f-e5ecd1491547_1536x737.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!jh9D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18f78c1-4733-43a3-906f-e5ecd1491547_1536x737.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jh9D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18f78c1-4733-43a3-906f-e5ecd1491547_1536x737.jpeg" width="1456" height="699" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e18f78c1-4733-43a3-906f-e5ecd1491547_1536x737.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:699,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HTMLMIX 24 API&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HTMLMIX 24 API" title="HTMLMIX 24 API" srcset="https://substackcdn.com/image/fetch/$s_!jh9D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18f78c1-4733-43a3-906f-e5ecd1491547_1536x737.jpeg 424w, https://substackcdn.com/image/fetch/$s_!jh9D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18f78c1-4733-43a3-906f-e5ecd1491547_1536x737.jpeg 848w, https://substackcdn.com/image/fetch/$s_!jh9D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18f78c1-4733-43a3-906f-e5ecd1491547_1536x737.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!jh9D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18f78c1-4733-43a3-906f-e5ecd1491547_1536x737.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The typical workflow looks like this:</p><ul><li><p><strong>Template preparation</strong>: The attacker creates a base phishing template with placeholder variables for personalization</p></li><li><p><strong>API integration</strong>: The template is submitted to HTMLMIX&#8217;s API endpoint with specified obfuscation parameters</p></li><li><p><strong>Variant generation</strong>: HTMLMIX returns multiple unique HTML variants, each with different obfuscation applied</p></li><li><p><strong>Email platform integration</strong>: These variants are fed into commodity SMTP services or compromised email accounts for distribution</p></li><li><p><strong>Redirect chaining</strong>: Links are processed through the Trust Redirects service or similar URL laundering platforms</p></li><li><p><strong>Campaign execution</strong>: Thousands of unique emails are distributed, each technically distinct despite originating from a single template</p></li></ul><p>The API documentation shows standard bearer token authentication and straightforward error handling. Rate limits exist (the API can be exhausted with heavy use), though the specific quota limits are not publicly disclosed.</p><p>HTMLMIX&#8217;s obfuscation service integrates directly with complementary attack infrastructure. The API can integrate with traditional email delivery methods, and the tool also has a partnership with a novel delivery system that will be the topic of an upcoming analysis.</p><h2>Defending Against AI-Powered Obfuscation</h2><p>HTMLMIX is just one tool among many, but it provides a clear view into where the threat landscape is heading. The question isn&#8217;t whether AI will transform phishing; it already has. The question is whether defenses will evolve quickly enough to keep pace.</p><p>What we&#8217;re witnessing is the early stage of AI-powered social engineering. The AI-powered features may currently feel somewhat gimmicky&#8212;e.g., the synonym generator produces inconsistent tone, and the thread fabrication creates contextual mismatches. But these capabilities will improve. Language models are advancing rapidly, and tools like HTMLMIX will integrate better models as they become available.</p><p>The phishing emails of 2026 will be more convincing than those of 2025, which are already more convincing than those of 2024. This trajectory demands that defenders move beyond reactive controls toward adaptive systems that can recognize novel evasion techniques.</p><p>Organizations that maintain security postures designed for yesterday&#8217;s threats will find themselves increasingly exposed. Defending against AI-powered phishing requires AI-powered defenses, coupled with fundamental security practices that remain effective regardless of technical sophistication.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.behindthesurface.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Behind the Surface Analysis Blog! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[I Saw a Phishing Site That Traps Security Bots ]]></title><description><![CDATA[I analyze dozens of phishing sites per month. Most are cut-and-paste redirects pointing to Phishing-as-a-Service kits. But this campaign was a little different.]]></description><link>https://www.behindthesurface.net/p/i-saw-a-phishing-site-that-traps</link><guid isPermaLink="false">https://www.behindthesurface.net/p/i-saw-a-phishing-site-that-traps</guid><dc:creator><![CDATA[Travis Simcox]]></dc:creator><pubDate>Tue, 20 Jan 2026 14:17:31 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/3acbe14d-71bc-4a54-8063-591c91b572d1_1200x723.avif" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Originally published: <a href="https://hackernoon.com/i-saw-a-phishing-site-that-traps-security-bots">I Saw a Phishing Site That Traps Security Bots | HackerNoon</a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R-eC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4900ccc8-5aa4-436e-970b-b3a90b841ffa_473x285.avif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R-eC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4900ccc8-5aa4-436e-970b-b3a90b841ffa_473x285.avif 424w, https://substackcdn.com/image/fetch/$s_!R-eC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4900ccc8-5aa4-436e-970b-b3a90b841ffa_473x285.avif 848w, https://substackcdn.com/image/fetch/$s_!R-eC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4900ccc8-5aa4-436e-970b-b3a90b841ffa_473x285.avif 1272w, https://substackcdn.com/image/fetch/$s_!R-eC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4900ccc8-5aa4-436e-970b-b3a90b841ffa_473x285.avif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R-eC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4900ccc8-5aa4-436e-970b-b3a90b841ffa_473x285.avif" width="473" height="285" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4900ccc8-5aa4-436e-970b-b3a90b841ffa_473x285.avif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:285,&quot;width&quot;:473,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:14605,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/avif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.behindthesurface.net/i/185182392?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4900ccc8-5aa4-436e-970b-b3a90b841ffa_473x285.avif&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!R-eC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4900ccc8-5aa4-436e-970b-b3a90b841ffa_473x285.avif 424w, https://substackcdn.com/image/fetch/$s_!R-eC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4900ccc8-5aa4-436e-970b-b3a90b841ffa_473x285.avif 848w, https://substackcdn.com/image/fetch/$s_!R-eC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4900ccc8-5aa4-436e-970b-b3a90b841ffa_473x285.avif 1272w, https://substackcdn.com/image/fetch/$s_!R-eC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4900ccc8-5aa4-436e-970b-b3a90b841ffa_473x285.avif 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I was analyzing a phishing kit last week when I noticed something in the HTML that shouldn't have been there: a hidden form field with no visible counterpart. Other parts of the code tracked mouse movements, keyboard presses, and clicks to verify human behavior. But buried at the bottom was a hidden input field programmatically added to the form, invisible to users, with the field name "website":<br><br><code>// Hidden honeypot field for bots<br>const honeypot = document.createElement('input');<br>honeypot.type = 'text';<br>honeypot.name = 'website';<br>honeypot.style.display = 'none';<br>form.appendChild(honeypot);<br><br>// Check if honeypot was filled (by bots)<br>form.addEventListener('submit', function() {<br>    if (honeypot.value !== '') {<br>        emailError.textContent = 'Security check failed.';<br>        emailError.style.display = 'block';<br>        return false;<br>    }<br>}<br><br></code>It wasn't part of the UI. The victim would never see it. So, why was it there? Because it wasn't designed to catch victims. <strong>It was designed to catch us.<br></strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.behindthesurface.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Behind the Surface Analysis Blog! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2><strong><br>The Invisible Tripwire<br></strong></h2><p><strong><br></strong>As a Cyber Threat Hunter, I analyze dozens of phishing sites per month. Most are either sloppy cut-and-paste jobs or subscription Phishing-as-a-Service kits. <strong><a href="https://www.youtube.com/shorts/QUgY7FoWOjU?ref=hackernoon.com">But this campaign was a little different</a></strong>. The landing page looked boring enough: a clean, corporate-styled prompt asking the user to "Verify your email address" before proceeding:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zCeM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f1c4b95-9980-4c71-b5b3-a3451fb37de7_1200x815.avif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zCeM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f1c4b95-9980-4c71-b5b3-a3451fb37de7_1200x815.avif 424w, https://substackcdn.com/image/fetch/$s_!zCeM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f1c4b95-9980-4c71-b5b3-a3451fb37de7_1200x815.avif 848w, https://substackcdn.com/image/fetch/$s_!zCeM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f1c4b95-9980-4c71-b5b3-a3451fb37de7_1200x815.avif 1272w, https://substackcdn.com/image/fetch/$s_!zCeM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f1c4b95-9980-4c71-b5b3-a3451fb37de7_1200x815.avif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zCeM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f1c4b95-9980-4c71-b5b3-a3451fb37de7_1200x815.avif" width="1200" height="815" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5f1c4b95-9980-4c71-b5b3-a3451fb37de7_1200x815.avif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:815,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:26109,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/avif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.behindthesurface.net/i/185182392?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f1c4b95-9980-4c71-b5b3-a3451fb37de7_1200x815.avif&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zCeM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f1c4b95-9980-4c71-b5b3-a3451fb37de7_1200x815.avif 424w, https://substackcdn.com/image/fetch/$s_!zCeM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f1c4b95-9980-4c71-b5b3-a3451fb37de7_1200x815.avif 848w, https://substackcdn.com/image/fetch/$s_!zCeM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f1c4b95-9980-4c71-b5b3-a3451fb37de7_1200x815.avif 1272w, https://substackcdn.com/image/fetch/$s_!zCeM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f1c4b95-9980-4c71-b5b3-a3451fb37de7_1200x815.avif 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><br>As expected, the contents of this field were sent on to the Adversary-in-the-Middle kit, in order to pre-file the email field on the credential request. But when I inspected the DOM, I found a discrepancy between what was rendered and what existed in the code.</p><p>Okay, this honeypot field technique isn&#8217;t actually new, and in fact, it has a legitimate pedigree. Web developers have used honeypot fields since the early 2000s to protect contact forms and registration pages. The logic is elegant: humans can&#8217;t see the hidden field, so they leave it empty. Spam bots parse the HTML, see an input called &#8220;website&#8221;, and dutifully fill it with a URL. Any submission with data in the honeypot gets silently discarded.</p><p>It&#8217;s a brilliant, passive defense. No CAPTCHA friction or user annoyance, just a quiet trap to catch automated abuse. And we see here how phishing operators have copied it, line for line, to catch us.</p><p>Here&#8217;s how it works in their context: Rudimentary security scanners parse raw HTML. When they encounter an input field, their programming compels them to fill it to test for vulnerabilities or trigger a submit action:</p><ul><li><p>Hidden field empty? Likely human, proceed to AitM proxy kit</p></li><li><p>Hidden field has data? Likely bot, display an error message<br></p></li></ul><h2><br><strong>The Engine Under the Hood: Traffic Cloaking</strong></h2><p></p><p>The honeypot is just one of the entry-level filters. Behind it sits a massive backend industry called Traffic Cloaking. Originally developed to both stop as well as perpetrate ad fraud, now weaponized for phishing. The sophisticated services cost $1000 per month and fingerprint every visitor in milliseconds. That&#8217;s not script kiddie money; that&#8217;s infrastructure investment. They&#8217;re checking:</p><p><strong>Behavioral biometrics:</strong> Mouse activity, typing rhythm. Humans are messy; bots are linear and instant.</p><p><strong>Device fingerprinting:</strong> Does <code>navigator.webdriver</code> return true? Does the WebGL renderer identify as &#8220;Google SwiftShader&#8221; (headless Chrome) instead of actual hardware?</p><p><strong>IP reputation:</strong> Residential ISP or a security vendor&#8217;s datacenter?<br><br><strong>Poisoning the Well</strong></p><p>Here&#8217;s where it gets devious. When phishing kits detect bots, scanners, and researchers, they don&#8217;t just block you. They serve a &#8220;Safe Page&#8221;:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8WZL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0436240c-1d6b-485e-a786-edf09f0e2984_3840x2295.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8WZL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0436240c-1d6b-485e-a786-edf09f0e2984_3840x2295.png 424w, https://substackcdn.com/image/fetch/$s_!8WZL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0436240c-1d6b-485e-a786-edf09f0e2984_3840x2295.png 848w, https://substackcdn.com/image/fetch/$s_!8WZL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0436240c-1d6b-485e-a786-edf09f0e2984_3840x2295.png 1272w, https://substackcdn.com/image/fetch/$s_!8WZL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0436240c-1d6b-485e-a786-edf09f0e2984_3840x2295.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8WZL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0436240c-1d6b-485e-a786-edf09f0e2984_3840x2295.png" width="1456" height="870" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0436240c-1d6b-485e-a786-edf09f0e2984_3840x2295.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:870,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Example safe page I grabbed from a popular phishing kit.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Example safe page I grabbed from a popular phishing kit." title="Example safe page I grabbed from a popular phishing kit." srcset="https://substackcdn.com/image/fetch/$s_!8WZL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0436240c-1d6b-485e-a786-edf09f0e2984_3840x2295.png 424w, https://substackcdn.com/image/fetch/$s_!8WZL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0436240c-1d6b-485e-a786-edf09f0e2984_3840x2295.png 848w, https://substackcdn.com/image/fetch/$s_!8WZL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0436240c-1d6b-485e-a786-edf09f0e2984_3840x2295.png 1272w, https://substackcdn.com/image/fetch/$s_!8WZL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0436240c-1d6b-485e-a786-edf09f0e2984_3840x2295.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Why? To poison threat intelligence feeds.</p><p>When a security vendor&#8217;s crawler lands on that blog, it categorizes the domain as, for example, &#8220;Retail&#8221; or &#8220;Technology/Benign.&#8221; That classification propagates to firewalls, URL filters, and blocklists, so the domain gets whitelisted. By the time a real victim clicks the link and sees the actual phishing page, the security tools have already stamped it safe.</p><p>I&#8217;ve watched domains stay active for weeks or even months using this technique. Without cloaking, most phishing sites get burned promptly.</p><h2><strong>The Mirror World: Defense Becomes Offense</strong></h2><p>It always makes me grin when I see that attackers often aren&#8217;t inventing new techniques, but they&#8217;re just copying ours.</p><p>Legitimate sites use honeypots to keep spam out of their databases, while phishing sites use honeypots to keep scanners out of their infrastructure. Same code, flipped context.</p><p>This pattern repeats everywhere:</p><p>CAPTCHA, originally designed to defend websites, now appears on at least 90% of phishing sites I analyze. Dual purpose:</p><p><strong>Technical:</strong> Stops automated crawlers from reaching the phishing content.</p><p><strong>Psychological:</strong> Builds trust. When victims see a Cloudflare Turnstile or Google reCAPTCHA, they think, &#8220;This site has security checks. It must be legitimate.&#8221;</p><h2><strong>What&#8217;s Behind the Curtain</strong></h2><p>Why work so hard to hide? Because what&#8217;s protected is valuable: real-time Adversary-in-the-Middle attacks that steal session cookies, not passwords. The kit acts as a live proxy, relaying credentials and 2FA codes to the actual service. When the real site issues a session cookie, the attacker snaps it up. No password needed, no 2FA bypass required. Just grab the token from the cookie, and you&#8217;re in. Search the inbox for monetizable content, like an invoice to replicate, and then burn it by sending out the next wave of phishing emails. That&#8217;s worth protecting with counter-intelligence.</p><h2><strong>How to Fight Back</strong></h2><h3><strong>1. Scan Like a Victim, Not a Server</strong></h3><p>Cloaking systems blacklist datacenter IPs instantly. In our hunt program, we route analysis traffic through residential and mobile proxies and mimic real hardware/software fingerprints, so we see what targets see. Be aware, though, that sometimes that means the page gets blocked by an ISP security appliance or DNS filtering.</p><h3><strong>2. Hunt for Negative Space</strong></h3><p>The honeypot I found was invisible to the eye but obvious as soon as I looked at the code (although, to be fair, this is because this landing page didn&#8217;t use any obfuscation). If feasible, update your detection rules to flag hidden form inputs on login pages.</p><h3><strong>3. Stop Teaching Users That CAPTCHAs Mean Safety</strong></h3><p>We spent years training users that a padlock icon and a CAPTCHA are good signs, and attackers know this. By now, attackers use CAPTCHA and SSL more than legitimate sites do.</p><p>Update your security awareness programs: A CAPTCHA on an unexpected link is not a safety feature. At best, it&#8217;s a gate designed to keep automated defenses out, and at worst it&#8217;s a ClickFix-style attack. If you have to solve a puzzle just to view a &#8220;shared internal document,&#8221; you&#8217;re walking into a trap.</p><h2><strong>The Arms Race Continues</strong></h2><p>Front-end honeypots on phishing sites are just one facet of a broader shift I&#8217;ve watched play out over the last few years: attackers treating their campaigns <strong><a href="https://www.behindthesurface.net/p/cleantraffic-the-redirect-service?ref=hackernoon.com">like legitimate SaaS products</a></strong>: optimizing uptime, managing bot traffic, A/B testing landing pages.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yuKH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaaf98f1-add2-4a23-a2ee-ba773712aa3d_3840x2036.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yuKH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaaf98f1-add2-4a23-a2ee-ba773712aa3d_3840x2036.jpeg 424w, https://substackcdn.com/image/fetch/$s_!yuKH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaaf98f1-add2-4a23-a2ee-ba773712aa3d_3840x2036.jpeg 848w, https://substackcdn.com/image/fetch/$s_!yuKH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaaf98f1-add2-4a23-a2ee-ba773712aa3d_3840x2036.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!yuKH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaaf98f1-add2-4a23-a2ee-ba773712aa3d_3840x2036.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yuKH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaaf98f1-add2-4a23-a2ee-ba773712aa3d_3840x2036.jpeg" width="1456" height="772" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/faaf98f1-add2-4a23-a2ee-ba773712aa3d_3840x2036.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:772,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;CleanTraffic: A typical traffic-cloaking portal to thwart detection of malicious sites.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="CleanTraffic: A typical traffic-cloaking portal to thwart detection of malicious sites." title="CleanTraffic: A typical traffic-cloaking portal to thwart detection of malicious sites." srcset="https://substackcdn.com/image/fetch/$s_!yuKH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaaf98f1-add2-4a23-a2ee-ba773712aa3d_3840x2036.jpeg 424w, https://substackcdn.com/image/fetch/$s_!yuKH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaaf98f1-add2-4a23-a2ee-ba773712aa3d_3840x2036.jpeg 848w, https://substackcdn.com/image/fetch/$s_!yuKH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaaf98f1-add2-4a23-a2ee-ba773712aa3d_3840x2036.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!yuKH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffaaf98f1-add2-4a23-a2ee-ba773712aa3d_3840x2036.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>CleanTraffic: A typical traffic-cloaking portal to thwart detection of malicious sites.</strong></p><p>We&#8217;re up against engineering teams with product roadmaps and customer support channels. The fix isn&#8217;t another poster about &#8220;hover over the link&#8221; or a longer PowerPoint about misspellings. It&#8217;s a mindset shift in which we stop treating phishing as a side quest. Attackers have already stolen our honeypots, our CAPTCHA, and our playbooks. The only real question now is whether we&#8217;re willing to steal something back from them: their discipline. If we can teach our defense teams to apply the science and art of analysis as effectively as attackers do, then the next time hidden code shows up in a phishing kit, it won&#8217;t be their tripwire. It&#8217;ll be ours.</p><p></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.behindthesurface.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Behind the Surface Analysis Blog! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Would you recognize the sound of a bank account being drained? How automated OTP social engineering bypasses MFA]]></title><description><![CDATA[Today we publish the first public findings on MrJayOTP.]]></description><link>https://www.behindthesurface.net/p/would-you-recognize-the-sound-of</link><guid isPermaLink="false">https://www.behindthesurface.net/p/would-you-recognize-the-sound-of</guid><dc:creator><![CDATA[Travis Simcox]]></dc:creator><pubDate>Sun, 02 Nov 2025 17:24:29 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/1a35b791-656f-48f9-be67-50b2477284ec_1280x1154.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>MITRE ATT&amp;CK Techniques: T1566 - Phishing; T1111 &#8211; Multi-Factor Authentication Interception; TA0006 &#8211; Credential Access</strong></p><p>Today we publish the first public findings on MrJayOTP, an operational &#8220;OTP bot&#8221; that turns phone calls into a high-velocity tool for harvesting one-time passcodes, all packaged in a SaaS solution with slick marketing. We&#8217;re also publishing an audio sample so defenders can hear how this works. This post walks through what we observed, why it matters, and what security teams should do now.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.behindthesurface.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Travis's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><strong>What is MrJayOTP?</strong></p><p>At a high level, MrJayOTP is a voice-first social-engineering platform packaged as a subscription-based service. It provides a single, integrated workflow for running scripted voice calls, compromising one-time passcodes in real time, and surfacing those codes to attackers who can then complete an authentication or transaction.</p><p>An attacker begins a process, such as account takeover or a money transfer, and hits an MFA request. Attack foiled, right? No. They send the target with the name of the service over to MrJayOTP, and with one click, the bot makes a phone call and obtains the MFA from the victim via social engineering.</p><p>The components of this attack aren&#8217;t new. The attacker could attempt to impersonate the bank themselves. Or they could grab some code off of GitHub, hook it into a compromised corporate 3CX phone switch (PBX), hook it into a voice generator AI, and run it on a local machine. In fact, the current iteration of MrJayOTP itself is at least number four in a product line from this developer dating back to 2021. But by packaging all of the needed components into a SaaS product, the barrier to entry for fraud becomes that much lower.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GHW3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6ef22b8-52da-4f3f-9bd1-0c0fe332ca4c_1280x493.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GHW3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6ef22b8-52da-4f3f-9bd1-0c0fe332ca4c_1280x493.png 424w, https://substackcdn.com/image/fetch/$s_!GHW3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6ef22b8-52da-4f3f-9bd1-0c0fe332ca4c_1280x493.png 848w, https://substackcdn.com/image/fetch/$s_!GHW3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6ef22b8-52da-4f3f-9bd1-0c0fe332ca4c_1280x493.png 1272w, https://substackcdn.com/image/fetch/$s_!GHW3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6ef22b8-52da-4f3f-9bd1-0c0fe332ca4c_1280x493.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GHW3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6ef22b8-52da-4f3f-9bd1-0c0fe332ca4c_1280x493.png" width="1280" height="493" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a6ef22b8-52da-4f3f-9bd1-0c0fe332ca4c_1280x493.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:493,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!GHW3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6ef22b8-52da-4f3f-9bd1-0c0fe332ca4c_1280x493.png 424w, https://substackcdn.com/image/fetch/$s_!GHW3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6ef22b8-52da-4f3f-9bd1-0c0fe332ca4c_1280x493.png 848w, https://substackcdn.com/image/fetch/$s_!GHW3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6ef22b8-52da-4f3f-9bd1-0c0fe332ca4c_1280x493.png 1272w, https://substackcdn.com/image/fetch/$s_!GHW3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6ef22b8-52da-4f3f-9bd1-0c0fe332ca4c_1280x493.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Several characteristics make the product noteworthy:</p><ul><li><p>Voice-based man-in-the-middle (MiTM): The platform&#8217;s primary vector is a phone call that targets the human step in multi-factor authentication. It is not malware, it is not a network interception tool, and it is not a browser prompt. Instead, it persuades the target &#8212; via audio &#8212; to reveal or enter a code.</p></li><li><p>OTP-agnostic capture: Captured codes may be delivered via SMS, generated by an authenticator app, or come from any other source. The platform exploits the human act of reading or entering the code rather than breaking the authentication algorithm.</p></li><li><p>Real-time DTMF/read-back capture: The system captures target keystrokes and read-back codes during the call and displays them immediately on the attacker&#8217;s screen, enabling real-time use. </p></li><li><p>Turnkey workflow and scale: MrJayOTP bundles caller-ID spoofing, multilingual synthetic voices, a growing list of pre-built modes (banks, brokerages, carriers, exchanges, payment gateways, cloud services, etc.), customizable scripts, and automation. That integration lowers the operational skill bar and enables higher-volume campaigns.</p></li></ul><p></p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;6d282047-7925-4ccc-9a9c-b3cddb776648&quot;,&quot;duration&quot;:null}"></div><p><strong>Why this is dangerous</strong></p><p>Security teams are staring to understand that OTP is a weaker MFA factor. Platforms like MrJayOTP change the risk calculus in several important ways:</p><ul><li><p>Caller-ID spoofing, paired with authoritative scripts and a sense of urgency, can make a call sound legitimate.</p></li></ul><ul><li><p>Human-centered bypass: The attack bypasses authentication by targeting a person. Even authenticator app codes and platform-based prompts are vulnerable if the target reads them aloud or types them on the phone keypad.</p></li><li><p>Scale and efficiency: By combining multiple features into one panel, the platform enables less sophisticated operators to execute high-volume attacks that previously required more skill and tool-chaining.<br></p></li></ul><p><strong>Defenders&#8217; checklist</strong></p><p>The following mitigations are practical and intentionally high-level.</p><ul><li><p>Move to phishing-resistant MFA where feasible. Promote FIDO2/security keys and platform-bound asymmetric credentials over SMS or other OTP-based systems.</p></li><li><p>Monitor call and authentication telemetry together. Correlate unusual call patterns with authentication attempts &#8212; e.g., a spike in inbound calls that precede high-value auth attempts, or abnormal DTMF activity.</p></li><li><p>Harden call-center and customer workflows. Train agents to avoid asking for OTPs, implement escalation paths for suspicious requests, and require out-of-band verification for high-value changes. </p></li><li><p>Improve user awareness. Educate users and team members on how this type of attack works. Click below to listen to a recording of a MrJayOTP bot request targeting John&#8217;s PayPal account.</p></li></ul><div class="native-audio-embed" data-component-name="AudioPlaceholder" data-attrs="{&quot;label&quot;:null,&quot;mediaUploadId&quot;:&quot;07c95299-258c-4c52-a3e5-3a54093df33c&quot;,&quot;duration&quot;:94.589386,&quot;downloadable&quot;:false,&quot;isEditorNode&quot;:true}"></div><p><strong>Back-end notes: </strong></p><p><strong>Telegram as a telemetry channel: </strong>During analysis we observed that the platform streams metadata &#8212; including target phone numbers and the services being impersonated &#8212; to a Telegram channel under admin control. This stream functions as a real-time activity log: it shows which numbers are being targeted and what brand or service the operator is portraying during each call.</p><p><strong>Azure AI</strong>: The bot hooks into Azure AI to generate the speech:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7Ash!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7649182c-3a8a-4d41-ae7a-46bba5b6b2f8_591x228.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7Ash!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7649182c-3a8a-4d41-ae7a-46bba5b6b2f8_591x228.png 424w, https://substackcdn.com/image/fetch/$s_!7Ash!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7649182c-3a8a-4d41-ae7a-46bba5b6b2f8_591x228.png 848w, https://substackcdn.com/image/fetch/$s_!7Ash!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7649182c-3a8a-4d41-ae7a-46bba5b6b2f8_591x228.png 1272w, https://substackcdn.com/image/fetch/$s_!7Ash!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7649182c-3a8a-4d41-ae7a-46bba5b6b2f8_591x228.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7Ash!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7649182c-3a8a-4d41-ae7a-46bba5b6b2f8_591x228.png" width="591" height="228" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7649182c-3a8a-4d41-ae7a-46bba5b6b2f8_591x228.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:228,&quot;width&quot;:591,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:167122,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://behindthesurface.substack.com/i/177794050?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7649182c-3a8a-4d41-ae7a-46bba5b6b2f8_591x228.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!7Ash!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7649182c-3a8a-4d41-ae7a-46bba5b6b2f8_591x228.png 424w, https://substackcdn.com/image/fetch/$s_!7Ash!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7649182c-3a8a-4d41-ae7a-46bba5b6b2f8_591x228.png 848w, https://substackcdn.com/image/fetch/$s_!7Ash!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7649182c-3a8a-4d41-ae7a-46bba5b6b2f8_591x228.png 1272w, https://substackcdn.com/image/fetch/$s_!7Ash!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7649182c-3a8a-4d41-ae7a-46bba5b6b2f8_591x228.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>Upstream services: </strong>The bot relies on an upstream provider for routing voice calls. Below is a screenshot from the developer&#8217;s device making payment for a route via cryptocurrency:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cBWF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f728952-0515-4401-a4b4-b42508e12b60_499x447.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cBWF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f728952-0515-4401-a4b4-b42508e12b60_499x447.png 424w, https://substackcdn.com/image/fetch/$s_!cBWF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f728952-0515-4401-a4b4-b42508e12b60_499x447.png 848w, https://substackcdn.com/image/fetch/$s_!cBWF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f728952-0515-4401-a4b4-b42508e12b60_499x447.png 1272w, https://substackcdn.com/image/fetch/$s_!cBWF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f728952-0515-4401-a4b4-b42508e12b60_499x447.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cBWF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f728952-0515-4401-a4b4-b42508e12b60_499x447.png" width="499" height="447" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1f728952-0515-4401-a4b4-b42508e12b60_499x447.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:447,&quot;width&quot;:499,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:123568,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://behindthesurface.substack.com/i/177794050?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f728952-0515-4401-a4b4-b42508e12b60_499x447.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cBWF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f728952-0515-4401-a4b4-b42508e12b60_499x447.png 424w, https://substackcdn.com/image/fetch/$s_!cBWF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f728952-0515-4401-a4b4-b42508e12b60_499x447.png 848w, https://substackcdn.com/image/fetch/$s_!cBWF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f728952-0515-4401-a4b4-b42508e12b60_499x447.png 1272w, https://substackcdn.com/image/fetch/$s_!cBWF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f728952-0515-4401-a4b4-b42508e12b60_499x447.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We can use that data to see payment flow. The upstream provider sends those payments to a Binance wallet:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pHfG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3b9d5f-82d1-4d57-87ea-dcf2ee14f97e_1286x360.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pHfG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3b9d5f-82d1-4d57-87ea-dcf2ee14f97e_1286x360.png 424w, https://substackcdn.com/image/fetch/$s_!pHfG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3b9d5f-82d1-4d57-87ea-dcf2ee14f97e_1286x360.png 848w, https://substackcdn.com/image/fetch/$s_!pHfG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3b9d5f-82d1-4d57-87ea-dcf2ee14f97e_1286x360.png 1272w, https://substackcdn.com/image/fetch/$s_!pHfG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3b9d5f-82d1-4d57-87ea-dcf2ee14f97e_1286x360.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pHfG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3b9d5f-82d1-4d57-87ea-dcf2ee14f97e_1286x360.png" width="1286" height="360" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3a3b9d5f-82d1-4d57-87ea-dcf2ee14f97e_1286x360.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:360,&quot;width&quot;:1286,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:176695,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://behindthesurface.substack.com/i/177794050?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3b9d5f-82d1-4d57-87ea-dcf2ee14f97e_1286x360.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pHfG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3b9d5f-82d1-4d57-87ea-dcf2ee14f97e_1286x360.png 424w, https://substackcdn.com/image/fetch/$s_!pHfG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3b9d5f-82d1-4d57-87ea-dcf2ee14f97e_1286x360.png 848w, https://substackcdn.com/image/fetch/$s_!pHfG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3b9d5f-82d1-4d57-87ea-dcf2ee14f97e_1286x360.png 1272w, https://substackcdn.com/image/fetch/$s_!pHfG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a3b9d5f-82d1-4d57-87ea-dcf2ee14f97e_1286x360.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>History: </strong>MrJayOTP has undergone a few iterations dating back to 2021:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!J0UF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb1def00-a85e-4b16-b35c-75ebcc0ef79c_1207x592.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!J0UF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb1def00-a85e-4b16-b35c-75ebcc0ef79c_1207x592.png 424w, https://substackcdn.com/image/fetch/$s_!J0UF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb1def00-a85e-4b16-b35c-75ebcc0ef79c_1207x592.png 848w, https://substackcdn.com/image/fetch/$s_!J0UF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb1def00-a85e-4b16-b35c-75ebcc0ef79c_1207x592.png 1272w, https://substackcdn.com/image/fetch/$s_!J0UF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb1def00-a85e-4b16-b35c-75ebcc0ef79c_1207x592.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!J0UF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb1def00-a85e-4b16-b35c-75ebcc0ef79c_1207x592.png" width="1207" height="592" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bb1def00-a85e-4b16-b35c-75ebcc0ef79c_1207x592.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:592,&quot;width&quot;:1207,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:390083,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://behindthesurface.substack.com/i/177794050?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb1def00-a85e-4b16-b35c-75ebcc0ef79c_1207x592.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!J0UF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb1def00-a85e-4b16-b35c-75ebcc0ef79c_1207x592.png 424w, https://substackcdn.com/image/fetch/$s_!J0UF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb1def00-a85e-4b16-b35c-75ebcc0ef79c_1207x592.png 848w, https://substackcdn.com/image/fetch/$s_!J0UF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb1def00-a85e-4b16-b35c-75ebcc0ef79c_1207x592.png 1272w, https://substackcdn.com/image/fetch/$s_!J0UF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb1def00-a85e-4b16-b35c-75ebcc0ef79c_1207x592.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong> <br>Closing thoughts</strong></p><p>Tools like MrJayOTP demonstrate a progression toward automation and AI on the social side of fraud. The controls that once worked at low scale can become brittle when paired with scripted persuasion and real-time capture. The best defenses combine phishing-resistant authentication, telemetry-driven detections, and ongoing user awareness training.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V16N!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b0eb3c1-4541-49b5-beb3-d96196c6cb57_962x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V16N!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b0eb3c1-4541-49b5-beb3-d96196c6cb57_962x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!V16N!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b0eb3c1-4541-49b5-beb3-d96196c6cb57_962x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!V16N!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b0eb3c1-4541-49b5-beb3-d96196c6cb57_962x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!V16N!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b0eb3c1-4541-49b5-beb3-d96196c6cb57_962x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V16N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b0eb3c1-4541-49b5-beb3-d96196c6cb57_962x1024.jpeg" width="284" height="302.3035343035343" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1b0eb3c1-4541-49b5-beb3-d96196c6cb57_962x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:962,&quot;resizeWidth&quot;:284,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!V16N!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b0eb3c1-4541-49b5-beb3-d96196c6cb57_962x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!V16N!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b0eb3c1-4541-49b5-beb3-d96196c6cb57_962x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!V16N!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b0eb3c1-4541-49b5-beb3-d96196c6cb57_962x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!V16N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b0eb3c1-4541-49b5-beb3-d96196c6cb57_962x1024.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.behindthesurface.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Travis's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CleanTraffic: The redirect service that is anything but clean]]></title><description><![CDATA[Did you know cybercriminals are using A/B testing to optimize their phishing campaigns?]]></description><link>https://www.behindthesurface.net/p/cleantraffic-the-redirect-service</link><guid isPermaLink="false">https://www.behindthesurface.net/p/cleantraffic-the-redirect-service</guid><dc:creator><![CDATA[Travis Simcox]]></dc:creator><pubDate>Sun, 02 Nov 2025 13:26:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!av_r!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ad6115c-5b87-43db-82f3-148cc22e321f_1260x668.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Did you know cybercriminals are using A/B testing to optimize their phishing campaigns? </p><p>We&#8217;ve recently uncovered CleanTraffic; a new filtering service being used to conceal malicious links from security tools.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.behindthesurface.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Travis's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>&#128269; How it works: </p><p>When someone clicks a protected link in a phishing email, CleanTraffic uses behavioral analytics like mouse movement to distinguish bots from real users:</p><p>Real users are funneled into the phishing flow.  </p><p>Bots and scanners are routed to harmless decoy pages.</p><p>This traffic filtering keeps malicious content off the radar. The platform even includes campaign analytics, much like legitimate marketing tools.&#128202;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!av_r!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ad6115c-5b87-43db-82f3-148cc22e321f_1260x668.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!av_r!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ad6115c-5b87-43db-82f3-148cc22e321f_1260x668.png 424w, https://substackcdn.com/image/fetch/$s_!av_r!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ad6115c-5b87-43db-82f3-148cc22e321f_1260x668.png 848w, https://substackcdn.com/image/fetch/$s_!av_r!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ad6115c-5b87-43db-82f3-148cc22e321f_1260x668.png 1272w, https://substackcdn.com/image/fetch/$s_!av_r!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ad6115c-5b87-43db-82f3-148cc22e321f_1260x668.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!av_r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ad6115c-5b87-43db-82f3-148cc22e321f_1260x668.png" width="1260" height="668" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3ad6115c-5b87-43db-82f3-148cc22e321f_1260x668.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:668,&quot;width&quot;:1260,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:330335,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://behindthesurface.substack.com/i/177793045?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ad6115c-5b87-43db-82f3-148cc22e321f_1260x668.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!av_r!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ad6115c-5b87-43db-82f3-148cc22e321f_1260x668.png 424w, https://substackcdn.com/image/fetch/$s_!av_r!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ad6115c-5b87-43db-82f3-148cc22e321f_1260x668.png 848w, https://substackcdn.com/image/fetch/$s_!av_r!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ad6115c-5b87-43db-82f3-148cc22e321f_1260x668.png 1272w, https://substackcdn.com/image/fetch/$s_!av_r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ad6115c-5b87-43db-82f3-148cc22e321f_1260x668.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As major CDN providers tighten abuse controls, threat actors are turning to such alternatives. Understanding these systems is key to tracking phishing operators who outsmart automated detections.</p><p>Have you encountered similar tradecraft in your investigations? Share your thoughts below! &#129504;  </p><p>#Cybersecurity #Phishing #ThreatIntelligence #Cybercrime</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.behindthesurface.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Travis's Substack! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Coming soon]]></title><description><![CDATA[This is Behind the Surface Analysis Blog.]]></description><link>https://www.behindthesurface.net/p/coming-soon</link><guid isPermaLink="false">https://www.behindthesurface.net/p/coming-soon</guid><dc:creator><![CDATA[Travis Simcox]]></dc:creator><pubDate>Sun, 02 Nov 2025 13:19:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QSgJ!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c55a869-412f-4d0c-b22e-8a281c4fe91c_811x811.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This is Behind the Surface Analysis Blog.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.behindthesurface.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.behindthesurface.net/subscribe?"><span>Subscribe now</span></a></p>]]></content:encoded></item></channel></rss>