SVG Phishing Malware Being Distributed with Analysis Obstruction Feature

April 1, 2025, 5:28 p.m.

Description

A sophisticated phishing malware using Scalable Vector Graphics (SVG) format has been identified. The malware embeds malicious scripts within SVG files, using Base64 encoding to bypass detection. It employs various techniques to obstruct analysis, including blocking automation tools, preventing specific keyboard shortcuts, disabling right-clicks, and detecting debugging attempts. The malware redirects users to a fake CAPTCHA page, which, when interacted with, leads to further malicious actions, potentially a phishing site impersonating Microsoft login pages. This evolving threat highlights the need for increased user vigilance, especially when dealing with SVG files from unknown sources.

Date

  • Created: April 1, 2025, 2:48 p.m.
  • Published: April 1, 2025, 2:48 p.m.
  • Modified: April 1, 2025, 5:28 p.m.

Attack Patterns

  • SVG Phishing Malware
  • T1036.002
  • T1556.002
  • T1185
  • T1550.001
  • T1221
  • T1027.002
  • T1204.001
  • T1059.007
  • T1027