Full Report
What security teams need to know about the latest wave of SVG attacks
Analysis Summary
# Tool/Technique: SVG-Borne Attacks (Malicious SVG Attachments)
## Overview
This technique involves weaponizing Scalable Vector Graphics (SVG) files to bypass email security filters. Unlike standard images, SVGs are XML-based, allowing them to carry executable content (JavaScript) and HTML. Attackers use these files to hide phishing forms, perform HTML smuggling for malware delivery, or redirect users to malicious infrastructure, leveraging the fact that many security policies treat .svg files as harmless image assets.
## Technical Details
- **Type:** Technique / Stager
- **Platform:** Cross-platform (any system with a modern web browser; primarily targeting Windows users via email)
- **Capabilities:** JavaScript execution, HTML Smuggling (Blob reassembly), credential harvesting, URL redirection, and obfuscation.
- **First Seen:** Significant volume increases noted in late 2025; major campaigns observed in February and August 2026.
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- T1566.001 - Phishing: Spearphishing Attachment
- **TA0005 - Defense Evasion**
- T1027.006 - Obfuscation/Decoding: HTML Smuggling
- T1036 - Masquerading (Image file spoofing)
- **TA0002 - Execution**
- T1204.002 - User Execution: Malicious File
## Functionality
### Core Capabilities
- **Script Execution:** As an XML-based format, SVGs can include `<script>` tags that execute in the browser context when the file is opened.
- **HTML Smuggling:** Reassembling malware payloads or archives (via Blobs) directly in the browser’s memory from encoded data within the SVG, bypassing network-level file inspections.
- **Credential Phishing:** Utilizing `<foreignObject>` tags and CSS to render pixel-perfect, full-screen login lures (e.g., Microsoft 365 login pages) locally.
### Advanced Features
- **Content-Type Spoofing:** Declaring `text/plain` on SVG attachments to confuse mail routing while relying on the browser to still execute the file as an SVG.
- **Automated Polymorphism:** Smuggling generators create per-sample junk elements and randomized identifiers to ensure each malicious attachment has a unique file hash.
- **Minimalist Redirects:** Some variants contain only a single line of plaintext code to navigate the browser to external C2 infrastructure, leaving no complex scripts for scanners to analyze.
## Indicators of Compromise
- **File Hashes (Broadcom/Symantec Detections):**
- Phish.Svg!gen2
- Scr.MalSvg!gen1 through gen5
- XSNet.Svg!gen1/gen2 (Machine Learning detections)
- **File Names:** Commonly use lures related to "Voicemail," "Sign-in," "Invoice," or "Document Viewer."
- **Network Indicators:**
- External infrastructure fronted by URL shorteners (often rotated rapidly).
- CAPTCHA gates used to block automated analysis bots.
- **Behavioral Indicators:**
- Browser process spawning a download of a secondary archive (ISO, ZIP, IMG) immediately after opening an SVG.
- SVG files containing `window.location` or `document.write` commands.
## Associated Threat Actors
- **Commodity Phishing Groups:** Widespread use for high-volume credential theft.
- **Malware Distributors:** Used as a first-stage stager for loaders and RATs (Remote Access Trojans).
## Detection Methods
- **Signature-based:** Traditional AV signatures (see file-based detections above), though effectiveness is limited by polymorphic generators.
- **Behavioral Detection:** Monitoring for browsers creating local Blobs or reassembling files from base64 strings immediately upon opening an image format.
- **Machine Learning:** Utilizing models (like XSNet) to identify structural anomalies in XML/SVG files that deviate from standard vector graphics.
- **Content Inspection:** Inspecting SVG files for the presence of `<script>`, `<iframe>`, or `<foreignObject>` tags.
## Mitigation Strategies
- **Email Policy:** Block or quarantine .svg attachments at the gateway, or treat them with the same scrutiny as .js or .hta files.
- **Mail Client Hardening:** Ensure inline rendering of SVGs is disabled (standard in modern versions of Outlook).
- **Browser Isolation:** Utilize web/email isolation technology to execute SVG attachments in a containerized environment away from the endpoint.
- **User Education:** Train users to be suspicious of image files that prompt for logins or trigger file downloads.
## Related Tools/Techniques
- **HTML Smuggling:** The underlying mechanism for reassembling payloads.
- **Script-First Attacks:** The broader trend of moving away from PE (Portable Executable) files to script-based stagers.
- **SVG Smuggling Generators:** Specialized toolkits used by attackers to mass-produce unique malicious SVGs.