Skip to main content

Ropemaker Email Vulnerability

A new email vulnerability named “Ropemaker” (Remotely Originated Post-delivery Email Manipulation Attacks Keeping Email Risky) has been discovered, using a Cascading Style Sheets (CSS) exploit to alter email bodies by hijacking them during transit.

Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A new email vulnerability named “Ropemaker” (Remotely Originated Post-delivery Email Manipulation Attacks Keeping Email Risky) has been discovered, using a Cascading Style Sheets (CSS) exploit to alter email bodies by hijacking them during transit.


Threat details

The vulnerability is exploited by switching the “display” function of various elements within the CSS of an email. This enables the threat actor sending an email with multiple links, some malicious and others non-malicious hiding the malicious while the email is in transit only displaying them once the email has been received.

When the attacker sends the email, they can alter it to only display the non-malicious links but can then alter the CSS file after the email has been delivered to disguise the non-malicious links, and only show the malicious ones. This allows the email to pass through some filtering methods that might be in place as the content of the email changes once it's been received.

A second exploit, called the “Ropemaker Matrix Exploit”, allows an attacker to recreate text by altering the visibility of certain letters using the CSS display rules.


Remediation advice

Mitigation:


Remediation steps

Type Step
  • * Don’t open any mail attachments you’re unsure of even if you trust the sender.
  • Ensure staff are properly trained on common phishing techniques.
  • Some settings may be available on certain email services that disable automatic execution of a remote resource.

Last edited: 31 January 2022 8:42 am