HomeSecurityPhishing: Using SVG files to avoid detection

Phishing: Using SVG files to avoid detection

Cybercriminals are increasingly using Scalable Vector Graphics (SVG) attachments in their phishing attacksto evade detection.

Phishing: Using SVG files to avoid detection

Most images on the internet are JPG or PNG files, which are made up of pixels. Each pixel has a specific color value and together they form the image.

SVG, or Scalable Vector Graphics, displays images differently. Instead of using pixels, images are created using lines, shapes, and text, which are described in mathematical formulas in the code. When opened in a browser, the file will create the graphics described in the text.

See also: Hive0145 hackers: Phishing attacks distribute Strela Stealer in Europe

Because they are vector images, they automatically resize without losing image quality or shape, making SVG files ideal for use in browser applications that may have different resolutions.

Phishing: Hackers use SVG attachments to avoid detection

We've seen SVG attachments used in phishing campaigns before . However, threat actors are now using them more and more, according to MalwareHunterTeam . SVG attachments allow for the display of graphics , but they can also be used to display HTML , using the <html> element.

This allows attackers to create SVG attachments that not only display images but also create phishing forms to steal credentials.

A recent SVG attachment [VirusTotal] displays a fake Excel spreadsheet with a login form embedded in it. If victims enter their details, they will be transferred to the attackers.

See also: Russian hackers exploit NTLM vulnerability to spread RAT Malware via Phishing emails

Other SVG attachments used in a recent phishing campaign [VirusTotal] are presented as official documents or requests for more information. Users are asked to click on a download button, which then downloads malware from a remote website.

Other campaigns use SVG attachments and embedded JavaScript toautomatically redirect browsers to websites hosting phishing forms when the image is opened.

The problem is that because these files are, for the most part, textual representations of images, they tend not to be detected as often by security software.

That said, users should be very careful with emails containing attachments as they may be a phishing.

See also: “GoIssue” phishing tool targets GitHub users

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

SVG phishing

Phishing protection

  • User education is crucial. Users need to be informed about phishing techniques and how to recognize suspicious messages or links.
  • Use phishing detection. There are tools and services that can detect and block attacks before they reach the end user.
  • Implement multi-factor authentication policies. This can include using one-time passwords, SMS verification, or using authentication apps.
  • Keep software and systems up to date. Software updates often include security fixes that can protect against phishing attacks.
  • Regularly check your logs and security reports to detect potential phishing attacks. Prevention is important, but knowing how and when a user was attacked can help prevent future attacks.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS