logo

Uncovering a Colombian Malware Campaign with AI Code Analysis

ID: e9432b3e-764b-533b-bc2b-c610713d5fc8

STIX ID: report--e9432b3e-764b-533b-bc2b-c610713d5fc8

Feed Name: VirusTotal Blog

Threat Score
70/100

Date Published: 2025-09-04

Date Updated: 2026-05-01

Author: Bernardo.Quintero

...
...

VirusTotal’s Code Insight analysis highlights that modern and legacy vector formats (SVG and SWF) remain abused by attackers: an undetected SVG family was found to contain embedded JavaScript that renders a phishing portal impersonating the Colombian Fiscalía and silently forces download of a malicious ZIP dropper. Using patterning (Spanish comments) and retrohunting, analysts linked dozens of undetected samples into a campaign showing polymorphism, obfuscation, email delivery, and at least 523 historical matches for a simple YARA signature.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.