216.73.217.22

SVG Smuggling - Image Embedded JavaScript Redirect Attacks

· Published 17/07/2025 13:13 · Modified 17/07/2025 19:47

Export JSON

Essential information

Published
17/07/2025 13:13
Modified
17/07/2025 19:47
Tags
2025-07-17 email spoofing javascript obfuscation phishing redirect svg xor encryption

Description

Threat actors are increasingly using Scalable Vector Graphics () files to deliver -based attacks. These SVGs contain embedded, obfuscated that initiates browser redirects to attacker-controlled infrastructure. The campaign uses and impersonation to deliver the SVGs, bypassing traditional file-based detection. The embedded code uses and reconstructs the command at runtime. The attack targets B2B Service Providers, including those handling corporate financial and employee data. Mitigation strategies include implementing DMARC policies, blocking attachments, and enhancing email security measures. The campaign demonstrates a shift towards smuggling techniques that avoid triggering traditional security alerts.

External references