Researchers at INKY observed a major phishing campaign that used SVG (Scalable Vector Graphics) image files to deliver malicious JavaScript. While abuse of SVG files isn’t new, INKY says their use in phishing campaigns has exploded over the past year.
“Between June 1 and August 4, 2026, INKY tracked and detected a sustained phishing campaign that used a deceptively simple lure — a missed voicemail notification — to deliver malicious code hidden inside an image file,” the researchers write. “The campaign reached 5,527 organizations and generated 26,589 detected emails. Every email was caught and flagged as dangerous. The attackers’ weapon of choice was a file format that most people, and many email filters, treat as harmless: the SVG image.”
The attackers timed the phishing emails to be sent on weekdays during working hours, so employees would be more likely to believe they were routine workplace notifications. Once a user opened the malicious file, they’d be taken to a phishing page designed to steal their credentials and multifactor authentication codes.
“The fetched content is generally a credential-harvesting page impersonating a widely used login such as Microsoft 365, Google Workspace or Adobe,” the researchers write. “In many campaigns the victim’s own email address is passed along and used to prefill the fake login form, making it look personalized and legitimate. Increasingly these pages are not simple clones but adversary-in-the-middle (AiTM) portals: they relay what the victim types to the real login service in real time, capture the resulting session token, and thereby defeat multifactor authentication. This technique has been tied to phishing-as-a-service kits such as Tycoon2FA, Mamba2FA and Sneaky2FA. Hosting the payload remotely also lets the attacker update or swap the phishing page at any time without ever changing the SVG that was delivered.”
KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce workforce risk.
Kaseya has the story: https://www.kaseya.com/blog/svg-smuggling-voicemail-phishing-campaign/
