Cybercriminals Exploit SVG Files For New Phishing Attacks

Cybercriminals have begun leveraging Scalable Vector Graphics (SVG) files to carry out phishing attacks, bypassing traditional email security measures, according to a report by Sophos. The attacks, which have escalated since mid-January, exploit the SVG file format’s ability to contain embedded scripts and active web content.

Unlike standard image formats such as JPEG or PNG, SVG files are XML-based and can include hyperlinks, scripts, and other interactive elements. This allows attackers to embed malicious links within seemingly harmless image files. When recipients open an infected SVG file, their browser automatically loads a phishing site designed to steal login credentials.

Sophos researchers found that attackers are disguising their phishing emails as legal documents, voicemail notifications, and payment confirmations. The emails often reference well-known services such as DocuSign, Microsoft SharePoint, Dropbox, and Google Voice. Once victims click on the embedded links, they are directed to fraudulent login pages that mimic legitimate platforms, capturing their usernames and passwords.

Some attacks even deploy CAPTCHA verification to appear more credible, while others use JavaScript to automatically redirect victims to phishing pages. More sophisticated variants of the attack have been observed, including SVG files embedded with malicious JavaScript that loads phishing sites without user interaction.

Sophos has developed a detection signature (Cxmail/EmSVG-C) to counter these threats. The company advises users to configure their systems to open SVG files with a text editor instead of a browser, reducing the risk of accidental exposure. Users are also urged to verify URLs before entering credentials and to remain cautious of unexpected email attachments.

Latest News

Must read