216.73.217.22

Pixel-Perfect Trap: The Surge of SVG-Borne Phishing Attacks

· Published 16/05/2025 08:51 · Modified 21/05/2025 21:08

Export JSON

Essential information

Published
16/05/2025 08:51
Modified
21/05/2025 21:08
Tags
2025-05-16 cybersecurity email security javascript obfuscation phaas phishing social engineering svg tycoon2fa ursnif
Related entities
4 observables, 9 techniques (mitre), 2 malware

Description

The Trustwave SpiderLabs team has identified a significant increase in image-based attacks, where seemingly harmless graphics are used to conceal dangerous links. Cybercriminals are exploiting the ability of files to embed , which can execute automatically upon opening. This technique has led to a 1800% increase in -based attacks in early 2025 compared to the previous year. The attacks are primarily driven by -as-a-Service () platforms like . These files are particularly dangerous because they can bypass traditional security measures and appear innocuous to users. The blog post analyzes various techniques used in these attacks and provides recommendations for protection, including blocking attachments, implementing advanced , and enhancing user awareness.

External references