logo

245% Increase in SVG Files Used to Obfuscate Phishing Payloads

ID: ad780fbc-49c2-55b5-b1a1-d8f333289917

STIX ID: report--ad780fbc-49c2-55b5-b1a1-d8f333289917

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2025-03-12

Date Updated: 2026-04-28

Author: KnowBe4 Threat Lab

...
...

KnowBe4 Threat Labs observed a sharp rise in phishing campaigns using SVG attachments (6.6% of malicious attachments Jan–Mar 2025, a 245% increase from Q4 2024, with a peak of 29.5% on March 4). Two campaigns are analyzed: polymorphic SVGs that load a transparent clickable overlay to redirect victims to Microsoft-branded credential harvesting pages, and personalized “missed message” SVGs that embed JavaScript to prefill and tag stolen credentials. The report explains how SVGs evade SEGs and native filters (XML text-based format, embedded/obfuscated JS, payload revealed on render), describes IOCs and techniques (polymorphic filenames, attachment names matching recipients, transparent <rect> overlays, two-stage redirects), and recommends contextual attachment inspection, metadata analysis, advanced NLP, and zero-trust evaluation to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.