245% Increase in SVG Files Used to Obfuscate Phishing Payloads
ID: ad780fbc-49c2-55b5-b1a1-d8f333289917
STIX ID: report--ad780fbc-49c2-55b5-b1a1-d8f333289917
Feed Name: KnowBe4 Blog
KnowBe4 Threat Labs observed a sharp rise in phishing campaigns using SVG attachments (6.6% of malicious attachments Jan–Mar 2025, a 245% increase from Q4 2024, with a peak of 29.5% on March 4). Two campaigns are analyzed: polymorphic SVGs that load a transparent clickable overlay to redirect victims to Microsoft-branded credential harvesting pages, and personalized “missed message” SVGs that embed JavaScript to prefill and tag stolen credentials. The report explains how SVGs evade SEGs and native filters (XML text-based format, embedded/obfuscated JS, payload revealed on render), describes IOCs and techniques (polymorphic filenames, attachment names matching recipients, transparent <rect> overlays, two-stage redirects), and recommends contextual attachment inspection, metadata analysis, advanced NLP, and zero-trust evaluation to mitigate the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
