Base64-encoding an SVG attack within an iframe and hiding it all in an EML attachment · Blog · Sublime Security
ID: 2fccc519-ae99-53ac-a25b-73a667d9eabf
STIX ID: report--2fccc519-ae99-53ac-a25b-73a667d9eabf
Feed Name: Sublime Security Blog
This Attack Spotlight describes a credential-phishing campaign that abused an attached EML file which autolaunched in some clients and contained an SVG disguised as a voicemail; the SVG hosted an iframe smuggling base64-encoded, custom-obfuscated HTML that delivered a fake Microsoft login page for credential theft, and Sublime used recursive file extraction (file.explode), base64 scanning (beta.scan_base64), and a deobfuscation routine to recover the payload URL and flag the message as malicious.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
