SVG Files Abused in Emerging Campaigns
ID: a891c6dc-2af9-584c-9264-74920fc6a46b
STIX ID: report--a891c6dc-2af9-584c-9264-74920fc6a46b
Feed Name: Cofense Blog
Threat Score
This report documents evolving abuse of SVG/HTML smuggling—facilitated by the AutoSmuggle tool—to bypass email gateways and deliver embedded payloads (ZIPs containing scripts and executables). It details two recent campaigns (Dec 2023 delivering XWorm RAT and Jan–Feb 2024 delivering Agent Tesla keylogger), describes multiple infection chains and email lure patterns, and highlights how threat actors modified AutoSmuggle-generated SVGs to evade detection and social-engineer victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
