VirusTotal has uncovered a sophisticated malware and phishing campaign that leverages SVG files to evade detection. This campaign uses SVG files as a vector to deliver malicious payloads and conduct phishing attacks, exploiting the trust users place in image files. The attackers embed hidden code within the SVG files, which when opened, can execute malicious scripts or redirect victims to phishing sites. This method allows the malware to bypass traditional security filters that often overlook image files. The discovery highlights the evolving tactics of cybercriminals who continuously adapt to security measures by using unconventional file types for attacks. Organizations and users are advised to exercise caution when handling SVG files, especially those received from untrusted sources. Enhanced security measures, including advanced file scanning and user awareness training, are critical to mitigating risks associated with such hidden threats. This incident underscores the importance of comprehensive cybersecurity strategies that consider all file types as potential attack vectors, reinforcing the need for vigilance in digital environments.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Sat, 06 Sep 2025 19:00:26 +0000