logo

Phishing emails increasingly use SVG attachments to evade detection

ID: c40bf9dc-56c4-50af-9db5-ec313c41d22a

STIX ID: report--c40bf9dc-56c4-50af-9db5-ec313c41d22a

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-11-17

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

The report details how threat actors are increasingly abusing SVG attachments to evade detection by embedding HTML and JavaScript that display phishing forms (e.g., fake Excel login pages) or download malware; samples uploaded to VirusTotal and reported by BleepingComputer show low vendor detections, making unsolicited SVGs particularly risky and recommending they be treated with suspicion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.