Uncovering a Colombian Malware Campaign with AI Code Analysis
ID: e9432b3e-764b-533b-bc2b-c610713d5fc8
STIX ID: report--e9432b3e-764b-533b-bc2b-c610713d5fc8
Feed Name: VirusTotal Blog
VirusTotal’s Code Insight analysis highlights that modern and legacy vector formats (SVG and SWF) remain abused by attackers: an undetected SVG family was found to contain embedded JavaScript that renders a phishing portal impersonating the Colombian Fiscalía and silently forces download of a malicious ZIP dropper. Using patterning (Spanish comments) and retrohunting, analysts linked dozens of undetected samples into a campaign showing polymorphism, obfuscation, email delivery, and at least 523 historical matches for a simple YARA signature.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
