Warning Against Malware in SVG Format Distributed via Phishing Emails
ID: 1a91eed3-385c-5cc7-8c8d-81d881f19b77
STIX ID: report--1a91eed3-385c-5cc7-8c8d-81d881f19b77
Feed Name: ASEC
Threat Score
AhnLab ASEC warns of an active campaign distributing malicious SVG attachments in phishing emails. Attackers embed JavaScript and hyperlink elements inside SVG image containers to either download a password-protected archive (containing AsyncRAT, a backdoor/infostealer) or present a phishing form that Base64-encodes and exfiltrates credentials; payloads are often hosted on legitimate services like Dropbox/Bitbucket and several MD5 hashes are listed as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
