Security researchers warned that attackers are increasingly weaponizing SVG files by embedding JavaScript and other active content into files that are often treated as harmless images. Recent campaigns used malicious SVG attachments and links for phishing, credential harvesting, malware delivery, and browser-based abuse, including fake voicemail lures, self-contained phishing pages rendered directly from the SVG, and redirectors that sent victims to attacker-controlled domains.
Analysis of recent samples found SVGs capable of obfuscated script execution, DOM manipulation, data exfiltration, and other in-browser actions that can bypass traditional defenses focused on conventional executables. Researchers linked one SVG-delivered script to a WordPress browser brute-force abuse pattern previously observed in 2024, while 2026 activity more commonly relied on redirects and embedded phishing content. Defenders were urged to treat SVGs as active executable content, inspect them for embedded scripts, and strengthen email and web filtering; published indicators included three domains and 22 SHA-1 hashes tied to the activity.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Gurucul published a high-severity threat research notice on malicious SVG abuse and provided indicators of compromise including three domains, 22 SHA-1 hashes, and detection queries. The notice recommended treating SVGs as executable content and strengthening email and web filtering.
ReversingLabs described an increase in malicious use of SVG files in early 2026, highlighting campaigns that used SVGs as redirectors, self-contained phishing pages, and script-enabled browser attack content. The analysis included fake voicemail-themed spearphishing attachments and SVGs that rendered full webpages while exfiltrating user input.
ReversingLabs reported that one analyzed script delivered via an SVG was associated with a 2024 browser brute-force abuse pattern targeting WordPress. The reference does not provide a specific date for when that 2024 activity occurred.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 25 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.