{"success":true,"data":{"id":"mamba-tycoon-obfuscated-html-b64-blob","label":"HTML smuggling — Blob/createObjectURL + large base64 payload in body (Mamba 2FA / Tycoon / QakBot pattern)","description":"HTML body contains a `new Blob()` or `URL.createObjectURL()` construct combined with a large base64 string (>=200 chars) — the HTML-smuggling delivery pattern for ZIPs, PEs, and PDFs behind the Mamba 2FA, Tycoon 2FA, and QakBot campaigns. Predictable payload headers (UEsDB for ZIP, TVpQA for PE, JVBER for PDF) add strong confidence. MITRE ATT&CK T1027.006. Bypasses URL reputation scanners entirely because the payload is reconstructed in the browser.","tier":"danger","category":"other","isThin":false}}