logo

New Wave Of Phishing Emails with SVG Files, (Tue, Jun 2nd)

ID: 9abbfe69-8bcf-59f7-bc17-e0cca6156b32

STIX ID: report--9abbfe69-8bcf-59f7-bc17-e0cca6156b32

Feed Name: SANS ISC Diary

Threat Score
55/100

Date Published: 2026-06-02

Date Updated: 2026-06-03

...
...

This report details a phishing campaign delivering malicious SVG attachments that contain minimal JavaScript (using application/ecmascript) which decodes a Base64+XOR payload and redirects victims to phishing pages hosted on domains using the cheap ".cfd" TLD (example: chinougoo.cfd). The technique aims to evade security tools that look for common script MIME types or simple JavaScript patterns, and the report includes code snippets, the XOR key construction, and a sample redirect, making it actionable for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.