Threats Tagged 'email attachments'
View all threats tagged with 'email attachments'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'email attachments'
Click on any threat for detailed analysis and mitigation recommendations
In October 2025, phishing emails predominantly delivered Trojan malware via attachments, accounting for 47% of cases. These attachments included scripts, documents, and compressed files, notably RAR archives containing JavaScript files. The phishing campaigns also involved distribution of Remcos RAT malware and used document attachments to download additional payloads. Korean phishing emails were specifically analyzed, revealing targeted case names, subjects, and attachment filenames. The report highlights evolving tactics such as increased use of compressed JS files and exploitation of OLE objects within documents. The threat leverages multiple MITRE ATT&CK techniques including persistence, command execution, and credential access. This medium-severity campaign poses significant risks through social engineering and malware delivery via email attachments, requiring focused defensive measures. No known exploits in the wild are reported, but the widespread use of common file formats and compression methods increases the attack surface. European organizations should be vigilant against these evolving phishing tactics and malware payloads. Join the discussion | AlienVault OTX General | 11/20/2025, 14:45:53 UTC Added: 11/20/2025, 22:13:41 UTC |
Attackers are exploiting Scalable Vector Graphics (SVG) files to execute sophisticated phishing attacks. SVGs, typically used for scalable images, can contain embedded JavaScript that executes when opened in a browser. The attack chain involves sending SVG attachments via spear-phishing emails or cloud storage links. When opened, the SVG file launches in the default web browser, allowing embedded scripts to execute and redirect victims to phishing sites mimicking trusted services. The attackers use deceptive subject lines and innocuous-looking attachment names to avoid suspicion. The SVG contains encrypted malicious code that, when decrypted, redirects to a phishing site protected by a Cloudflare CAPTCHA gate. Organizations are advised to implement deep content inspection, disable automatic SVG rendering, educate employees, and monitor for unusual redirects and script activity. Join the discussion | AlienVault OTX General | 08/07/2025, 21:14:50 UTC Added: 08/07/2025, 21:47:44 UTC |
Showing 1 to 2 of 2 results