An unprecedented malware campaign began circulating in early August 2025, via email attachments and web downloads, targeting users in Colombia and beyond.
See also: Stealerium malware targets educational institutions

Using two different vector-based file formats – Adobe Flash SWF and Scalable Vector Graphics (SVG) – the attackers designed a multi-phase operation that evaded traditional antivirus detection .
Initial reports emerged when a SWF file with a seemingly innocent name, Sequester.swf, triggered alarms in a small number of antivirus engines, prompting deeper investigation.
Within days, a companion SVG file appeared, incorporating sophisticated JavaScript payloads designed to mimic the portal of the Fiscalía General de la Nación . The seamless transition between old and modern formats surprised many security teams.
The SWF component pretended to be a legitimate 3D puzzle game, complete with ActionScript units for rendering, pathfinding, and cryptographic routines. While antivirus engines flagged the encrypted classes and AES routines, they failed to recognize that this code served legitimate game mechanics rather than malicious behavior.
At the same time, the SVG variant contained embedded JavaScript that decoded a Base64 phishing page and silently downloaded a ZIP file containing additional payloads. The combination of these two vectors created a multi-headed threat that evaded detection barriers with alarming ease.
See also: TinyLoader: New malware loader attacks Windows users

VirusTotal analysts noted that by expanding support for SWF and SVG analysis in Code Insight, they were able to discover dozens of related samples within hours of the initial submissions. By searching for Spanish-language comments left by the attackers – strings such as “POLIFORMISMO_MASIVO_SEGURO” and “Funciones dummy MASIVAS” – the researchers identified a coherent campaign spanning more than 40 unique SVG files, none of which had raised alarms in standard antivirus scans.
The early presence of these indicators allowed for rapid signature generation and recursive search operations, yielding over 500 matches when applied to submissions from the previous year. The heart of the operation lay in the circumvention tactics. By distributing large, encrypted SWF files that combined game code with cryptographic routines, the attackers exploited heuristic thresholds.
At the same time, SVG files embedded encrypted JavaScript in CDATA sections, avoiding simple pattern matching. When rendered to a browser, the script decoded and inserted a phishing HTML, complete with progress bars and authentic forms that mimicked official government communications.
Central to the success of this campaign was the layer of obfuscation and polymorphism. Each SWF sample used variable renaming, junk code injection, and custom packaging routines to defeat static analysis. This rule achieved over 523 detections when rerouted to one year's worth of submissions.
See also: 'Sindoor Dropper': New malware campaign targets Linux

Combining heuristic thresholds, encrypted payloads, and deliberate deception, the attackers demonstrated a sophisticated understanding of both legacy and modern file formats – highlighting the urgent need for content-aware analysis in modern threat defense.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
