216.73.217.22

Scalable Vector Graphics files pose a novel phishing threat

· Published 05/02/2025 20:51 · Modified 06/02/2025 01:29

Export JSON

Essential information

Published
05/02/2025 20:51
Modified
06/02/2025 01:29
Tags
2025-02-05 browser-based attacks credential-theft email attachments evasion techniques file format abuse nymeria phishing social engineering svg troj/autoit-dhb
Related entities
13 techniques (mitre), 1 malware

Description

Cybercriminals are exploiting the file format to conduct attacks that bypass existing anti-spam and anti- protection. These attacks involve email messages with . file attachments, which open in the default browser on Windows computers. The files contain anchor tags and scripts that link to malicious web pages, often disguised as legal documents or voicemails. When victims click on the embedded links, they are directed to pages that mimic popular services like DocuSign, Microsoft SharePoint, and Office365. The attackers use various techniques and sophisticated methods to capture and exfiltrate user credentials. Some files even contain encoded malware. To protect against this threat, users are advised to change the default program for opening files and be cautious of suspicious emails.

External references