logo

Cybercriminals Weaponize Graphics Files in Phishing Attacks

ID: acf19e2d-cde7-5cef-838e-92c499aced26

STIX ID: report--acf19e2d-cde7-5cef-838e-92c499aced26

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2025-02-07

Date Updated: 2026-04-22

...
...

Sophos researchers report an active phishing campaign abusing SVG image files to bypass email/security filters and present convincing, embedded login dialogs (often impersonating DocuSign, SharePoint, Dropbox, Microsoft) that capture and exfiltrate credentials to attacker-controlled domains or services; the technique has been observed since late 2024 and accelerated in January 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.