Isc.Sans.Edu SVG Phishing Campaign Exploits Email Security Gaps
Article Content
- •SVG phishing emails exploit a gap in email security, increasing risks for organizations.
- •Malicious SVG files contain obfuscated JavaScript that executes silently in browsers.
- •The campaign has seen a fifty-fold increase in SVG-based phishing attempts in 2025.
A new phishing campaign is leveraging SVG files to bypass email security measures, as reported by SANS. These SVG files contain obfuscated JavaScript that executes upon opening, redirecting users to credential-harvesting sites. The campaign has seen a dramatic rise, with a fifty-fold increase in malicious SVG attachments in 2025. Notably, Microsoft tracked 1.2 million phishing emails delivered to over 53,000 organizations across 23 countries in February 2026. The SVG files are disguised as ordinary images, making them difficult for security tools to detect. The payload is encoded using Base64 and XOR encryption, complicating automated analysis. This tactic highlights a significant blind spot in current email security defenses, particularly for organizations that have fortified against traditional threats like malicious PDFs and Office documents. Security teams are urged to update their detection rules to address this new vector.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Continue Reading
UAT-10147 Cybercrime Group Integrates AI for Large-Scale Attacks In early 2026, Cisco Talos identified UAT-10147, a Chinese-speaking cybercrime group targeting vulnerable web servers across multiple countries, including Brazil, China, and Canada. The group employs agentic AI to enhance its attack methods, transitioning from simple scripting to semi-autonomous offensive operations.…
UAT-10147 Threat Actor Deploys SPECTRE Backdoor with AI and EDR Bypass Techniques UAT-10147, a Chinese-speaking threat actor, has been identified using the SPECTRE backdoor and a Linux rootkit to conduct sophisticated multi-platform attacks. The group employs advanced techniques such as Bring Your Own Vulnerable Driver (BYOVD) to disable endpoint detection and response (EDR) protections. Cisco…