Phishing Campaign Targets Employees with Malicious SVG Files

KnowBe4 Team | Sep 11, 2026

Researchers at INKY observed a major phishing campaign that used SVG (Scalable Vector Graphics) image files to deliver malicious JavaScript. While abuse of SVG files isn’t new, INKY says their use in phishing campaigns has exploded over the past year.

“Between June 1 and August 4, 2026, INKY tracked and detected a sustained phishing campaign that used a deceptively simple lure — a missed voicemail notification — to deliver malicious code hidden inside an image file,” the researchers write. “The campaign reached 5,527 organizations and generated 26,589 detected emails. Every email was caught and flagged as dangerous. The attackers’ weapon of choice was a file format that most people, and many email filters, treat as harmless: the SVG image.”

The attackers timed the phishing emails to be sent on weekdays during working hours, so employees would be more likely to believe they were routine workplace notifications. Once a user opened the malicious file, they’d be taken to a phishing page designed to steal their credentials and multifactor authentication codes.

“The fetched content is generally a credential-harvesting page impersonating a widely used login such as Microsoft 365, Google Workspace or Adobe,” the researchers write. “In many campaigns the victim’s own email address is passed along and used to prefill the fake login form, making it look personalized and legitimate. Increasingly these pages are not simple clones but adversary-in-the-middle (AiTM) portals: they relay what the victim types to the real login service in real time, capture the resulting session token, and thereby defeat multifactor authentication. This technique has been tied to phishing-as-a-service kits such as Tycoon2FA, Mamba2FA and Sneaky2FA. Hosting the payload remotely also lets the attacker update or swap the phishing page at any time without ever changing the SVG that was delivered.”

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce workforce risk.

Kaseya has the story: https://www.kaseya.com/blog/svg-smuggling-voicemail-phishing-campaign/

 

See KnowBe4 Cloud Email Security in Action

Request a personalized demo today to see how KnowBe4's Cloud Email Security products will enhance your email security.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, email and collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.