Increase In Phishing SVG Attachments, (Thu, Nov 21st)
ID: a072866f-2d4a-519b-8525-fa1c8fb4e0a5
STIX ID: report--a072866f-2d4a-519b-8525-fa1c8fb4e0a5
Feed Name: SANS ISC Diary
The report analyzes a phishing campaign that uses SVG attachments with embedded HTML/JavaScript to render blurry images and present credential-phishing forms. Attackers embed PNG images as data URIs, hardcode victim email addresses in base64, and dynamically retrieve organization logos (via logo.clearbit.com) to personalize forms; stolen credentials are POSTed to attacker-controlled endpoints. Multiple samples were identified on VirusTotal, and one sample includes heavily obfuscated JavaScript indicating attempts to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
