logo

Watch out for SVG files booby-trapped with malware

ID: d1156af8-d225-55f4-be3b-ba1f38f74449

STIX ID: report--d1156af8-d225-55f4-be3b-ba1f38f74449

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
70/100

Date Published: 2025-09-22

Date Updated: 2026-05-01

...
...

The report documents a Latin America (primarily Colombia) phishing campaign that weaponizes oversized SVG files—embedding the full payload inside XML “SVG smuggling” lures that render fake judicial portals in the browser, prompt a password-protected ZIP download, and ultimately install AsyncRAT via DLL sideloading; the campaign produces unique, likely AI-generated files per target and includes sample indicators (SHA1, detection name) and telemetry showing active detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.