20.7 C
Canberra
Saturday, October 25, 2025

VirusTotal finds hidden malware phishing marketing campaign in SVG recordsdata


VirusTotal finds hidden malware phishing marketing campaign in SVG recordsdata

VirusTotal has found a phishing marketing campaign hidden in SVG recordsdata that create convincing portals impersonating Colombia’s judicial system that ship malware.

VirusTotal detected this marketing campaign after it added help for SVGs to its AI Code Perception platform.

VirusTotal’s AI Code Perception function analyzes uploaded file samples utilizing machine studying to generate summaries of suspicious or malicious habits discovered within the recordsdata.

After including help for SVGs, VirusTotal discovered an SVG file that had zero detections by antivirus scans, however whose AI-powered Code Perception function detected utilizing JavaScript to show HTML, impersonating a portal for Colombia’s authorities judiciary system.

VirusTotal Code insights detecting a malicious SVG file
VirusTotal Code insights detecting a malicious SVG file
Supply: VirusTotal

SVG, or Scalable Vector Graphics, is used to generate pictures of traces, shapes, and textual content by means of textual mathematical formulation within the file.

Nevertheless, risk actors have begun more and more utilizing SVG recordsdata in assaults, as they will also be used to show HTML utilizing the aspect and execute JavaScript when the graphic is loaded.

Within the marketing campaign found by Virustotal, SVG picture recordsdata are used to render faux portals that show a phony obtain progress bar, in the end prompting the person to obtain a password-protected zip archive [VirusTotal]. The password for this file is displayed within the faux portal web page.

“As proven within the screenshots under, the faux portal is rendered precisely as described, simulating an official authorities doc obtain course of,” explains VirusTotal.

“The phishing website consists of case numbers, safety tokens, and visible cues to construct belief, all of it crafted inside an SVG file.”

Fake portal for Colombia’s judicial system​​​​​​​
Pretend portal for Colombia’s judicial system
Supply: VirusTotal

BleepingComputer discovered that the extracted file accommodates 4 recordsdata: a respectable executable from the Comodo Dragon net browser, renamed to be an official judicial doc, a malicious DLL [VirusTotal], and what seems to be two encrypted recordsdata.

Extracted password-protected archive
Extracted password-protected archive
Supply: BleepingComputer

If the person opens the executable, the malicious DLL will likely be sideloaded to put in additional malware on the system.

After detecting this preliminary SVG, VirusTotal recognized 523 beforehand uploaded SVG recordsdata that had been a part of the identical marketing campaign however had evaded detection by safety software program.

The addition of SVG help to AI Code Insights was essential in exposing this specific marketing campaign, as VirusTotal famous that using AI makes it simpler to determine new malicious campaigns.

“That is the place Code Perception helps most: giving context, saving time, and serving to deal with what actually issues. It is not magic, and it will not exchange skilled evaluation, nevertheless it’s yet another instrument to chop by means of the noise and get to the purpose quicker,” concludes VirusTotal.

46% of environments had passwords cracked, almost doubling from 25% final 12 months.

Get the Picus Blue Report 2025 now for a complete take a look at extra findings on prevention, detection, and information exfiltration traits.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

[td_block_social_counter facebook="tagdiv" twitter="tagdivofficial" youtube="tagdiv" style="style8 td-social-boxed td-social-font-icons" tdc_css="eyJhbGwiOnsibWFyZ2luLWJvdHRvbSI6IjM4IiwiZGlzcGxheSI6IiJ9LCJwb3J0cmFpdCI6eyJtYXJnaW4tYm90dG9tIjoiMzAiLCJkaXNwbGF5IjoiIn0sInBvcnRyYWl0X21heF93aWR0aCI6MTAxOCwicG9ydHJhaXRfbWluX3dpZHRoIjo3Njh9" custom_title="Stay Connected" block_template_id="td_block_template_8" f_header_font_family="712" f_header_font_transform="uppercase" f_header_font_weight="500" f_header_font_size="17" border_color="#dd3333"]
- Advertisement -spot_img

Latest Articles