Blog | Trinity Cyber

When Trusted Websites Deliver Malicious Content

Written by Mike Denning | Aug 19, 2026, 1:18:01 PM

Making the Case for Secure Web Gateway Modernization

One of your users receives an invoice notice with a link that opens a SharePoint instance. The domain belongs to a platform the business uses every day. Understandably, your user thinks, “This is safe.”

Your Secure Web Gateway (SWG) allowed the connection because the destination was trusted. But the content inside it was malicious. 

The above attack pattern is not a hypothetical. Microsoft documented Storm-0324 using phishing lures that led victims to malicious files hosted on SharePoint. And the problem is broader than one campaign or platform. Google Safe Browsing says it examines billions of URLs each day and finds thousands of new unsafe sites, many being legitimate websites that have been compromised.

Destination Trust is Not Enough

SWGs are foundational, enforcing acceptable-use, logging who went where, and blocking risky sites. These capabilities remain critical. Traditional SWGs were designed to enforce acceptable use policy, not to stop sophisticated attacks delivered through services users already trust.

Trinity Cyber researchers have observed this risk in the wild. In one recent campaign, legitimate e-commerce websites unknowingly delivered Magecart-style payment skimming code through a multi-stage attack chain that retrieved malicious JavaScript from blockchain-hosted smart contracts before streaming additional payloads over WebSockets. 

We have also observed attackers abusing trusted websites to deliver modern ClickFix campaigns. Our research into the ErrTraffic toolkit found malicious JavaScript planted on legitimate websites that dynamically retrieved payload infrastructure from blockchain smart contracts, before presenting convincing browser-based social engineering lures to victims. Again, the destination website was legitimate, the malicious content delivered within the session was the threat.

Further, in payment card security, PCI SSC's 2025 e-skimming guidance lists unauthorized scripts on legitimate payment pages as a real control problem. A domain's reputation can be accurate while the content delivered in a specific session is dangerous. 

Even conventional file inspection can miss the decisive detection moment. MITRE ATT&CK describes HTML smuggling as a technique that hides malicious data inside seemingly benign HTML or JavaScript. The browser then reconstructs the file on the endpoint. In other words, the complete malicious file may never traverse the gateway as a recognizable file.  

The Industry Added Band-Aids, Instead of Addressing Root Cause  

To date, the industry has largely responded with band-aids: more IOC-based detections and additional tools such as near-line sandboxing and Remote Browser Isolation (RBI). These technologies can address specific gaps, but they can also add cost and complexity while frustrating users and leaving the same reactive underlying security model in place.

For security leaders, the consequences are significant:

  • Threats bypass the gateway and push risk downstream where it is more costly to address
  • Increased team workload chasing alerts and false positives
  • Increased breach risk and incident response needs

Security Leaders Must Ask a Different Question

Beyond enforcing policy, can a modern gateway pull its weight in stopping attacks before they enter your environment? Does the SWG simply determine whether the destination is trusted, or does it perform robust examination after the connection is allowed? URL reputation alone cannot provide the complete answer.

Instead of focusing exclusively on policy enforcement and reputation services, security leaders must evaluate how effective a gateway’s detections are at identifying adversary TTPs, enabling low-cost and low-friction TLS inspection, contextually understanding complete network sessions, and preventing malicious content from reaching users in the first place.

Evaluating Modern SWGs: A Practical Guide

What a SWG should be has changed significantly, and the criteria for evaluation has not kept pace. Trinity Cyber addresses these gaps, combining traditional SWG policy controls with patented Full Content Inspection™ (FCI) that edits threats out of live sessions, stopping malicious content before it reaches users. Protection happens with less than one millisecond of inspection latency, and with a false positive rate under .01%. The Trinity Cyber platform is proven, performing over two trillion inspections per day, down to the sub-object level, across industries.

Our eBook, What Security Leaders Should Expect from a Modern SWG, explains how to evaluate that capability, and questions to ask before selecting a replacement. 

Download the eBook to learn: 

  • Why traditional SWGs struggle against modern attack techniques
  • What capabilities should define a modern Secure Web Gateway
  • How to evaluate solutions based on security outcomes, not feature checklists
  • How to modernize web security without replacing your entire security architecture