Phishing attacks leveraging HTML code inside SVG files
#1
Bug 
Quote:With each passing year, phishing attacks feature more and more elaborate techniques designed to trick users and evade security measures. Attackers employ deceptive URL redirection tactics, such as appending malicious website addresses to seemingly safe links, embed links in PDFs, and send HTML attachments that either host the entire phishing site or use JavaScript to launch it. Lately, we have noticed a new trend where attackers are distributing attachments in SVG format, the kind normally used for storing images.

SVG format

SVG (Scalable Vector Graphics) is a format for describing two-dimensional vector graphics using XML. This is how an SVG file appears when opened in image viewing software.

[Image: svg-phishing1.png]
SVG image

But if you open it in a text editor, you can see the XML markup that describes the image. This markup allows for easy editing of image parameters, eliminating the need for resource-intensive graphics editors.

[Image: svg-phishing3.png]This is what an SVG file looks like when opened in a text editor

Since SVG is based on XML, it supports JavaScript and HTML, unlike JPEG or PNG. This makes it easier for designers to work with non-graphical content like text, formulas, and interactive elements. However, attackers are exploiting this by embedding scripts with links to phishing pages within the image file.

[Image: svg-phishing4.png]Sample SVG file with embedded HTML code. The tag introduces HTML markup

Phishing email campaigns leveraging SVG files

At the start of 2025, we observed phishing emails that resembled attacks with an HTML attachment, but instead utilized SVG files.

Continue Reading...
Reply


Messages In This Thread
Phishing attacks leveraging HTML code inside SVG files - by harlan4096 - 21 April 25, 08:36

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AnyDesk 8.0.3 for Linux
Version 8.0.3 for ...harlan4096 — 09:05
Google Chrome 149.0.7827.196/197
Google Chrome 149....harlan4096 — 09:04
System Restore Evolved: Windows 11 Point...
Imagine if a bad d...harlan4096 — 09:01
Avast 26.6.11050 & AVG 26.6.11050
Avast 26.6.11050 :...harlan4096 — 18:11
Mozilla Firefox Browser 152.0.2
Mozilla Firefox Br...harlan4096 — 18:09

[-]
Birthdays
Today's Birthdays
avatar (40)efynu
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>