Ropemaker Email Vulnerability
A new email vulnerability named “Ropemaker” (Remotely Originated Post-delivery Email Manipulation Attacks Keeping Email Risky) has been discovered, using a Cascading Style Sheets (CSS) exploit to alter email bodies by hijacking them during transit.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
A new email vulnerability named “Ropemaker” (Remotely Originated Post-delivery Email Manipulation Attacks Keeping Email Risky) has been discovered, using a Cascading Style Sheets (CSS) exploit to alter email bodies by hijacking them during transit.
Threat details
The vulnerability is exploited by switching the “display” function of various elements within the CSS of an email. This enables the threat actor sending an email with multiple links, some malicious and others non-malicious hiding the malicious while the email is in transit only displaying them once the email has been received.
When the attacker sends the email, they can alter it to only display the non-malicious links but can then alter the CSS file after the email has been delivered to disguise the non-malicious links, and only show the malicious ones. This allows the email to pass through some filtering methods that might be in place as the content of the email changes once it's been received.
A second exploit, called the “Ropemaker Matrix Exploit”, allows an attacker to recreate text by altering the visibility of certain letters using the CSS display rules.
Remediation advice
Mitigation:
Remediation steps
Last edited: 31 January 2022 8:42 am