Scripting Vector Grifts: SVG phishing with smuggled JS and adversary in the middle tactics · Blog · Sublime Security
ID: 466fb27e-2906-5e3f-8557-26497c17b2eb
STIX ID: report--466fb27e-2906-5e3f-8557-26497c17b2eb
Feed Name: Sublime Security Blog
This report describes an active credential-phishing campaign that uses malicious SVG attachments containing embedded JavaScript to redirect victims to attacker-controlled pages that perform fake verification and a spoofed Microsoft login. The attack implements an AITM technique that forwards harvested credentials to the real Microsoft authentication service for validation, increasing the likelihood of capturing valid credentials; Sublime details detection signals (embedded JS in SVG, voicemail lures, unknown senders) and its detection rule that blocks these emails.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
