SVG Phishing Malware Being Distributed with Analysis Obstruction Feature
Essential information
- Published
- 01/04/2025 14:48
- Modified
- 01/04/2025 17:28
- Tags
- 2025-04-01 analysis obstruction base64 captcha microsoft impersonation phishing svg svg phishing malware vector graphics xml
- Related entities
- 9 techniques (mitre), 1 malware
Description
A sophisticated phishing malware using Scalable Vector Graphics (SVG) format has been identified. The malware embeds malicious scripts within SVG files, using Base64 encoding to bypass detection. It employs various techniques to obstruct analysis, including blocking automation tools, preventing specific keyboard shortcuts, disabling right-clicks, and detecting debugging attempts. The malware redirects users to a fake CAPTCHA page, which, when interacted with, leads to further malicious actions, potentially a phishing site impersonating Microsoft login pages. This evolving threat highlights the need for increased user vigilance, especially when dealing with SVG files from unknown sources.