A Closer Look at Malicious SVG Phishing
ID: dbf009d7-e808-5484-b52e-4e4f9cc38ea5
STIX ID: report--dbf009d7-e808-5484-b52e-4e4f9cc38ea5
Feed Name: Binary Defense Blog
This report details recent phishing campaigns that weaponize SVG files to execute or load malicious JavaScript, enabling redirections to credential-harvesting sites while evading common defenses due to SVGs’ benign reputation and limited inspection by security tools. It explains why traditional detection struggles (hash variance, limited EDR visibility, email client rendering), and offers a behavioral detection approach including entropy checks, script tag and external reference detection, and high-signal hunting queries for Microsoft Defender/Sentinel, CrowdStrike, and SentinelOne to surface suspicious SVG activity, especially when initiated by Outlook.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
