ThreatCluster

SVG-Based DCRat Campaign Delivers Malware via Phishing Emails

First seen 15 Aug 2026, 10:35 UTC GbhackersCybersecuritynews 78% similarity 59

Article Content

Browse articles
ThreatCluster

A new campaign utilizing DarkCrystal RAT (DCRat) has been identified, where threat actors employ SVG files disguised as legal notifications to deliver malware. The campaign begins with phishing emails urging users to open the SVG attachment, which reconstructs a password-protected archive directly in the browser. This method leverages HTML smuggling techniques to bypass traditional security measures. The Trellix Advanced Research Center investigated the operation after a customer escalation, revealing the sophisticated nature of the attack. Victims are primarily individuals receiving these phishing emails, which appear legitimate and harmless. The campaign highlights the evolving tactics of cybercriminals in malware delivery. Current status indicates that organizations should remain vigilant against such phishing attempts.

Key Points: • DCRat campaign uses SVG files to deliver malware through phishing emails. • Attackers employ HTML smuggling to reconstruct malware archives in browsers. • Victims are targeted with legal notification lures, making detection challenging.

ThreatCluster AI How this analysis works

Timeline

2026-08-14
DCRat campaign identified
Trellix ARC reported a new DCRat campaign using SVG files for malware delivery via phishing emails.
Gbhackers
2026-08-14
Phishing emails reported
Phishing emails posing as legal notifications were identified, urging recipients to open SVG attachments.
Cybersecuritynews

Community

Browse all →