Toot

Written by Fellows on 2025-01-21 at 19:14

If you’re not blocking SVG (Scalable Vector Graphic) attachments in email messages you might want to.

I have observed something I haven’t yet seen. Malicious email messages where the attachment the threat actor wants the target to open is a to SVG file pretending to be an agreement.

The SVG file when loaded makes a HTTP call to load a remote image, it also contains a transparent layer which links to the malicious website.

Looks to be an attempt at evading detection.

[#]ThreatIntel

=> More informations about this toot | View the thread | More toots from fellows@cyberplace.social

Mentions

Tags

=> View threatintel tag

Proxy Information
Original URL
gemini://mastogem.picasoft.net/toot/113867939413237014
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
219.443656 milliseconds
Gemini-to-HTML Time
0.597813 milliseconds

This content has been proxied by September (3851b).