logo

Phishing attacks leveraging HTML code inside SVG files

ID: a46d3d50-9fd5-5113-ba96-8d3125544b33

STIX ID: report--a46d3d50-9fd5-5113-ba96-8d3125544b33

Feed Name: Securelist by Kaspersky

Threat Score
50/100

Date Published: 2025-04-21

Date Updated: 2026-04-29

Author: Roman Dedenok

...
...

Phishing actors are increasingly using SVG image attachments (which can contain embedded HTML/JavaScript) to host or launch credential-harvesting pages and redirection scripts. Kaspersky telemetry observed a rising trend in early 2025, with 2,825 SVG-bearing phishing emails in Q1 and 1,324 in the first half of April, indicating active campaigns that can bypass some defenses by presenting as images while executing web-based phishing behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.