logo

Threat Actors Exploit SVG Files in Stealthy JavaScript Redirects

ID: 4b30c34b-0453-5f8a-90c2-76fff4224c42

STIX ID: report--4b30c34b-0453-5f8a-90c2-76fff4224c42

Feed Name: Infosecurity Magazine (News)

Threat Score
60/100

Date Published: 2025-07-15

Date Updated: 2026-04-22

...
...

A phishing campaign is abusing SVG image files by embedding JavaScript that decrypts a secondary payload via a static XOR key and redirects victims in-browser to attacker-controlled domains (often with Base64 tracking). Attackers use spoofed sender addresses, geofencing, and short-lived randomized domains to evade detection while targeting B2B service providers; recommended mitigations include blocking or stripping scripts from SVGs, enforcing DMARC, enabling Safe Links/Safe Attachments, and improving telemetry to detect browser-based pivots.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.