Threats Tagged '.svg'
View all threats tagged with '.svg'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged '.svg'
Click on any threat for detailed analysis and mitigation recommendations
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers. Join the discussion | AlienVault OTX General | 07/17/2026, 20:08:00 UTC Added: 07/18/2026, 08:55:18 UTC |
A malware campaign in Latin America uses oversized SVG files containing the full malicious payload to deliver AsyncRAT, a remote access trojan. The attack employs social engineering via emails impersonating trusted institutions with urgent legal warnings, primarily targeting Colombia. Clicking the SVG file opens a fake judicial portal to deceive victims. The campaign uses DLL sideloading to evade detection and AI-generated templates for customization. This method avoids external connections by embedding the payload directly in the SVG file. Attacks peaked mid-week in August, focusing on judicial system impersonation. No CVSS score is available, but the threat is medium severity due to its stealth and control capabilities. European organizations should be aware of this evolving tactic as it could be adapted to target other regions. Vigilance against suspicious SVG attachments and advanced detection techniques are critical for defense. Join the discussion | AlienVault OTX General | 11/09/2025, 04:31:57 UTC Added: 11/10/2025, 11:35:31 UTC |
Tykit is a newly identified phishing kit targeting Microsoft 365 accounts, active since May 2025. It uses SVG files as delivery vectors and a multi-stage attack chain to mimic Microsoft login pages and steal credentials. The kit employs evasion techniques including Cloudflare Turnstile anti-bot protection and basic anti-debugging measures. It primarily targets industries such as finance, construction, IT, professional services, government, and telecom, with victims globally including the EMEA region. Stolen credentials are exfiltrated via API calls to attacker-controlled servers. The campaign requires user interaction through phishing but does not require prior authentication. This threat poses a medium severity risk due to its potential impact on confidentiality and the widespread use of Microsoft 365 in Europe. Join the discussion | AlienVault OTX General | 10/21/2025, 21:49:29 UTC Added: 10/22/2025, 08:03:32 UTC |
A phishing campaign targeting Ukrainian government entities uses malicious SVG files to initiate an infection chain. The attack begins with emails containing SVG attachments that redirect victims to a download site. A CHM file is then used to execute a remote HTA loader, which delivers two malware payloads: Amatera Stealer and PureMiner. Amatera Stealer harvests extensive information from infected systems, including credentials, system data, application data, browser files, and cryptocurrency wallets. PureMiner collects hardware information and monitors system activity to deploy efficient CPU or GPU mining modules. The campaign demonstrates sophisticated techniques, including fileless malware delivery and the use of multiple stages to evade detection. Join the discussion | AlienVault OTX General | 09/26/2025, 20:06:05 UTC Added: 09/29/2025, 09:22:21 UTC |
A sophisticated malware campaign has been uncovered that utilizes various techniques to deliver Remote Access Trojans (RATs) such as XWorm and Remcos. The attack chain begins with a ZIP archive, often hosted on trusted platforms like ImgKit, containing obfuscated BAT scripts. These scripts execute PowerShell-based loaders that inject RAT payloads directly into memory, enabling fileless execution. The campaign also employs SVG files with embedded JavaScript to trigger the malware download, exploiting non-traditional file formats to evade detection. The infection process involves multiple stages, including persistence mechanisms, PowerShell script execution, and the use of loaders to decrypt and deploy the final payload. This evolving threat landscape highlights the need for advanced security measures to counter such sophisticated attacks. Join the discussion | AlienVault OTX General | 09/11/2025, 16:40:48 UTC Added: 09/11/2025, 17:15:59 UTC |
Attackers are exploiting Scalable Vector Graphics (SVG) files to execute sophisticated phishing attacks. SVGs, typically used for scalable images, can contain embedded JavaScript that executes when opened in a browser. The attack chain involves sending SVG attachments via spear-phishing emails or cloud storage links. When opened, the SVG file launches in the default web browser, allowing embedded scripts to execute and redirect victims to phishing sites mimicking trusted services. The attackers use deceptive subject lines and innocuous-looking attachment names to avoid suspicion. The SVG contains encrypted malicious code that, when decrypted, redirects to a phishing site protected by a Cloudflare CAPTCHA gate. Organizations are advised to implement deep content inspection, disable automatic SVG rendering, educate employees, and monitor for unusual redirects and script activity. Join the discussion | AlienVault OTX General | 08/07/2025, 21:14:50 UTC Added: 08/07/2025, 21:47:44 UTC |
Threat actors are increasingly using Scalable Vector Graphics (SVG) files to deliver JavaScript-based redirect attacks. These SVGs contain embedded, obfuscated JavaScript that initiates browser redirects to attacker-controlled infrastructure. The campaign uses email spoofing and impersonation to deliver the SVGs, bypassing traditional file-based detection. The embedded code uses XOR encryption and reconstructs the redirect command at runtime. The attack targets B2B Service Providers, including those handling corporate financial and employee data. Mitigation strategies include implementing DMARC policies, blocking SVG attachments, and enhancing email security measures. The campaign demonstrates a shift towards smuggling techniques that avoid triggering traditional security alerts. Join the discussion | AlienVault OTX General | 07/17/2025, 13:13:10 UTC Added: 07/17/2025, 19:31:10 UTC |
Showing 1 to 7 of 7 results