logo

Hackers Weaponize SVG Files and Office Documents to Target Windows Users

ID: 4d5bfd75-30a3-5a14-b6ad-4e54abfeaff7

STIX ID: report--4d5bfd75-30a3-5a14-b6ad-4e54abfeaff7

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-20

Date Updated: 2026-04-21

Author: Dhivya

...
...

Researchers uncovered a sophisticated multi-vector phishing campaign targeting manufacturing and government organizations in Italy, Finland, and Saudi Arabia that uses weaponized Office documents (CVE-2017-11882), malicious SVGs/LNKs, and RAR-wrapped JavaScript to initiate a four-stage loader. The chain includes steganographically embedded .NET assemblies hosted on legitimate services, a trojanized TaskScheduler library, in-memory payload loading and process hollowing into RegAsm.exe, plus a UAC bypass to deploy information stealers and RATs (PureLog, Katz, DC Rat, Async Rat, Remcos); recommended mitigations include enhanced email filtering, disabling legacy Equation Editor components, inspecting image attachments, and monitoring PowerShell/process activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.