Phishing Emails Use SVG Files to Avoid Detection

Stu Sjouwerman | Nov 22, 2024

Image Based PhishingPhishing emails are increasingly using Scalable Vector Graphics (SVG) attachments to display malicious forms or deliver malware, BleepingComputer reports. 

SVG is an image format that’s stored in XML text files, allowing users to create an image through XML code by specifying shapes, colors, and text. Threat actors are using these files to craft convincing phishing forms that can bypass security filters.

“SVG attachments used in a recent campaign pretend to be official documents or requests for more information, prompting you to click the download button, which then downloads malware from a remote site,” BleepingComputer says.

“Other campaigns utilize SVG attachments and embedded JavaScript to automatically redirect browsers to sites hosting phishing forms when the image is opened. The problem is that since these files are mostly just textual representations of images, they tend not to be detected by security software that often. From samples seen by BleepingComputer and uploaded to VirusTotal, at the most, they have one or two detections by security software.”

Users should be on the lookout for SVG attachments, since they aren’t commonly used by most businesses. If an SVG file displays what looks like an Excel spreadsheet with a login portal, for example, it’s certainly a phishing attempt.

“Receiving an SVG attachment is not common for legitimate emails, and should immediately be treated with suspicion,” BleepingComputer says. “Unless you are a developer and expect to receive these types of attachments, it is safer to delete any emails containing them.”

New-school security awareness training can keep your employees up-to-date on evolving social engineering tactics so they can thwart these types of phishing attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

BleepingComputer has the story.

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.