logo

Judicial Notification Phish Targets Colombian Users – .SVG Attachment Deploys Info-stealer Malware

ID: 0b0ef262-47e4-5242-88a5-eeb1bb9d78b3

STIX ID: report--0b0ef262-47e4-5242-88a5-eeb1bb9d78b3

Feed Name: Seqrite Blog

Threat Score
75/100

Date Published: 2025-10-13

Date Updated: 2026-04-30

Author: Prashil Moon

...
...

Executive summary: This report analyzes a targeted Spanish-language phishing campaign impersonating a Colombian judicial office that uses a malicious SVG attachment to stage an HTA/VBS/PowerShell chain, which downloads and decodes a .NET loader that fetches an injector and AsyncRAT; the campaign employs anti-VM and AMSI-evasion techniques, in-memory process injection (MSBuild.exe), persistence (Run key / scheduled task / startup shortcut), and capabilities for data collection and encrypted C2 exfiltration. The analysis includes file MD5s, detection names, and mapped MITRE ATT&CK TTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.