Phishing Emails Use SVG Files to Avoid Detection
ID: 47d3c294-3406-5c2b-afed-4f3834d3aa2c
STIX ID: report--47d3c294-3406-5c2b-afed-4f3834d3aa2c
Feed Name: KnowBe4 Blog
Threat actors are increasingly abusing SVG email attachments—leveraging their XML-based, text-heavy format and embedded JavaScript—to display fraudulent forms, auto-redirect to phishing sites, or trigger malware downloads while evading many security detections. Recent campaigns reported by BleepingComputer show very low antivirus hits on VirusTotal, underscoring the need for users to treat unsolicited SVGs as suspicious, especially those mimicking documents or login prompts; organizations are urged to strengthen user awareness to counter these phishing tactics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
