Phishing attacks leveraging HTML code inside SVG files
ID: a46d3d50-9fd5-5113-ba96-8d3125544b33
STIX ID: report--a46d3d50-9fd5-5113-ba96-8d3125544b33
Feed Name: Securelist by Kaspersky
Threat Score
Phishing actors are increasingly using SVG image attachments (which can contain embedded HTML/JavaScript) to host or launch credential-harvesting pages and redirection scripts. Kaspersky telemetry observed a rising trend in early 2025, with 2,825 SVG-bearing phishing emails in Q1 and 1,324 in the first half of April, indicating active campaigns that can bypass some defenses by presenting as images while executing web-based phishing behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
