Full Report
Build personalized, realistic phishing scenarios with Huntress Custom HTML for Custom Phishing, tailored to your organization's unique risks and vendors.
Analysis Summary
# Tool/Technique: Huntress Custom HTML for Custom Phishing
## Overview
Custom HTML for Custom Phishing is a specialized feature within the Huntress Security Awareness Training (SAT) platform. It allows administrators to create highly personalized, realistic phishing simulations by utilizing a direct HTML editor. The purpose of this tool is to move beyond generic templates and build scenarios that mimic an organization's specific internal communication styles, vendors, and tools to increase employee vigilance against Business Email Compromise (BEC) and targeted phishing.
## Technical Details
- **Type:** Phishing Simulation Tool / Social Engineering Framework
- **Platform:** Web-based (Targeting Windows, macOS, Linux, and Mobile users via email)
- **Capabilities:**
- Direct HTML editing for complete email customization.
- Integration of organization-specific branding, logos, and tone.
- Link sanitization to prevent accidental malicious use.
- Click-to-compromise tracking and analytics.
- **First Seen:** July 16, 2026 (Published Date)
## MITRE ATT&CK Mapping
- **[TA0001 - Initial Access]**
- **[T1566 - Phishing]**
- **[T1566.001 - Spearphishing Attachment]**
- **[T1566.002 - Spearphishing Link]**
- **[TA0007 - Discovery]**
- **[T1589.002 - Gather Victim Identity Information: Email Addresses]** (Simulated)
- **[TA0001 - Initial Access]**
- **[T1566.003 - Spearphishing via Service]**
## Functionality
### Core Capabilities
- **HTML Scrubber/Sanitizer:** Automatically cleans custom code to ensure the simulation does not contain live malicious payloads or unauthorized tracking.
- **Visual Replication:** Allows admins to copy the exact look and feel of internal IT support requests, healthcare supplier portals, or manufacturing operational alerts.
- **Performance Analytics:** Measures the "click-to-compromise" rate to identify which departments or user groups are most vulnerable to specific lures.
### Advanced Features
- **Persona Emulation:** Enables the creation of emails that match the specific "voice" and "tone" of internal executives or established third-party vendors.
- **Real-World Reproduction:** Allows security teams to take a real phishing email caught by their filters and recreate it as a safe training exercise for the entire staff.
- **Hybrid Campaign Management:** Works alongside "Managed Phishing" scenarios which are updated monthly based on active SOC data.
## Indicators of Compromise
*Note: As this is a legitimate simulation tool, these indicators refer to the simulated "threats" generated by the platform.*
- **Network Indicators:**
- `phishingdefense[.]org` (Defanged domain used for training links)
- **Behavioral Indicators:**
- Unexpected requests for credential entry via high-fidelity replicas of Microsoft Teams or Google OAuth consent screens.
- Urgency-based requests for invoice payments or payroll updates mimicking known vendors.
## Associated Threat Actors
While this is a defensive tool, it is designed to simulate the tactics of:
- **BEC Groups:** Financial fraudsters targeting accounting departments.
- **APT Groups:** Using spearphishing for initial entry.
- **General Phishing Operations:** Utilizing emerging techniques like "ClickFix" and "BitB" (Browser-in-the-Browser).
## Detection Methods
- **Behavioral Detection:** Identifying deviations in standard communication patterns (e.g., a "vendor" sending an email from an unusual domain, even if the body content is perfect).
- **Email Security Stacks:** Flagging simulated emails that lack proper SPF/DKIM alignment if not whitelisted for training.
- **User Reporting:** The primary "detection" success metric is the frequency at which employees use the "Report Phishing" button rather than clicking.
## Mitigation Strategies
- **Multi-Factor Authentication (MFA):** Essential to prevent the use of credentials harvested through high-fidelity phishing pages.
- **Security Awareness Training:** Regularly rotating between generic managed templates and the highly specific "Custom HTML" scenarios described here.
- **Policy Enforcement:** Establishing out-of-band verification processes for financial transactions or password resets.
## Related Tools/Techniques
- **Gophish:** An open-source phishing framework.
- **King-Phisher:** Another common tool for testing and promoting user awareness.
- **Deepfake Meeting Invites:** A modern technique referenced in the article where attackers use fake video conference lures.
- **OAuth Consent Phishing:** A technique where users are tricked into granting permissions to a malicious third-party app.