logo

GUloader Unmasked: Decrypting the Threat of Malicious SVG Files

ID: 603d8197-c38c-561d-a137-e5fcc38873fb

STIX ID: report--603d8197-c38c-561d-a137-e5fcc38873fb

Feed Name: McAfee Labs Blog

Threat Score
72/100

Date Published: 2024-02-29

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Labs analysis describes a GUloader campaign distributed through malicious SVG attachments that use embedded JavaScript to drop a ZIP containing an obfuscated WSF; the WSF launches PowerShell to fetch base64-encoded payloads from a remote URL, decode shellcode, and perform process hollowing into MSBuild for execution and persistence, with indicators (SHA256 hashes and URL) provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.