logo

SVG Files Abused in Emerging Campaigns

ID: a891c6dc-2af9-584c-9264-74920fc6a46b

STIX ID: report--a891c6dc-2af9-584c-9264-74920fc6a46b

Feed Name: Cofense Blog

Threat Score
70/100

Date Published: 2024-03-13

Date Updated: 2026-04-27

Author: Cofense

...
...

This report documents evolving abuse of SVG/HTML smuggling—facilitated by the AutoSmuggle tool—to bypass email gateways and deliver embedded payloads (ZIPs containing scripts and executables). It details two recent campaigns (Dec 2023 delivering XWorm RAT and Jan–Feb 2024 delivering Agent Tesla keylogger), describes multiple infection chains and email lure patterns, and highlights how threat actors modified AutoSmuggle-generated SVGs to evade detection and social-engineer victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.