logo

Base64-encoding an SVG attack within an iframe and hiding it all in an EML attachment · Blog · Sublime Security

ID: 2fccc519-ae99-53ac-a25b-73a667d9eabf

STIX ID: report--2fccc519-ae99-53ac-a25b-73a667d9eabf

Feed Name: Sublime Security Blog

Threat Score
55/100

Date Published: 2026-01-08

Date Updated: 2026-05-01

...
...

This Attack Spotlight describes a credential-phishing campaign that abused an attached EML file which autolaunched in some clients and contained an SVG disguised as a voicemail; the SVG hosted an iframe smuggling base64-encoded, custom-obfuscated HTML that delivered a fake Microsoft login page for credential theft, and Sublime used recursive file extraction (file.explode), base64 scanning (beta.scan_base64), and a deobfuscation routine to recover the payload URL and flag the message as malicious.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.