A new attack campaign is using HTML smuggling and data blobs to deliver malware onto victim machines. The attack, dubbed Duri, was first detected in early July of this year and is currently active. Attackers can deploy the download using Data URLs on the client device, or they can create a JavaScript blob with the correct MIME-type, which results in a download on the target device. Traditional network security tools, such as proxies, firewalls, and sandboxes, depend on the transfer of objects over the wire to flag malicious activity.”]

