Attackers are increasingly abusing Scalable Vector Graphics (SVG) email attachments as active initial-access payloads rather than harmless images. Because SVG is XML that browsers can interpret, a file opened locally can embed scripts, display full-screen credential-phishing content, reconstruct smuggled archives, or silently redirect a victim without placing a conspicuous URL in the email body. One analyzed sample concealed a Base64-encoded iframe containing obfuscated JavaScript that reversed and transformed encoded data into a destination URL before redirecting the browser; the file had four VirusTotal detections at the time of analysis.
SVG-based campaigns surged during 2026, including a Microsoft-observed operation that sent 1.2 million messages to more than 53,000 organizations, while telemetry showed a sharp increase in SVG detections in August. Most campaigns conduct broad credential theft, but targeted activity in Latin America, particularly Colombia, has used judicial and tax-themed lures to deliver AsyncRAT, Remcos, and DCRat. Organizations should treat SVG attachments as executable active content, inspect their XML and embedded objects, and apply layered email filtering, attachment sandboxing, endpoint controls, and web protections.

Get the infrastructure and lures behind it.
8 events from the most recent confirmed update back to the earliest known activity.
The first half of September recorded 9,659 SVG-attributed detections, corresponding to a rate roughly 70% higher than the June and July average.
SVG-attributed detections rebounded to 26,433, nearly double the preceding six-month average and 142% above the June trough.
A voicemail-themed SVG campaign generated approximately 26,500 detections across 5,500 organizations during the June-to-August period.
Reported SVG-attributed detections declined to 10,909, representing a 60% decrease from October 2025 across eight months. The decline was assessed as attackers rotating attachment formats rather than abandoning SVG attacks.
Microsoft observed an SVG phishing campaign that sent 1.2 million messages to more than 53,000 organizations across 23 countries. The campaign used a CAPTCHA gate followed by a fake sign-in page.
Reported SVG-attributed detections reached 27,443, a level later used as the starting point for an eight-month decline in detections.
Microsoft stopped rendering inline SVG content in Outlook, limiting that delivery route. Conventional SVG attachments could still be delivered and opened directly in a browser.
A malicious SVG was found to embed a Base64-encoded iframe and obfuscated JavaScript that reconstructs a destination URL and redirects the browser. The sample had four VirusTotal detections, while its destination site was unreachable at the time of analysis.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.