SVG-Based DCRat Campaign Delivers Malware via Phishing Emails
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A new campaign utilizing DarkCrystal RAT (DCRat) has been identified, where threat actors employ SVG files disguised as legal notifications to deliver malware. The campaign begins with phishing emails urging users to open the SVG attachment, which reconstructs a password-protected archive directly in the browser. This method leverages HTML smuggling techniques to bypass traditional security measures. The Trellix Advanced Research Center investigated the operation after a customer escalation, revealing the sophisticated nature of the attack. Victims are primarily individuals receiving these phishing emails, which appear legitimate and harmless. The campaign highlights the evolving tactics of cybercriminals in malware delivery. Current status indicates that organizations should remain vigilant against such phishing attempts.
Key Points: • DCRat campaign uses SVG files to deliver malware through phishing emails. • Attackers employ HTML smuggling to reconstruct malware archives in browsers. • Victims are targeted with legal notification lures, making detection challenging.