Malicious SVG Attachments Resurface: Credential Phishing and Malware Delivery via Image Files
What Happened — Attackers are embedding malicious scripts in SVG files, a format that many email filters treat as harmless. Recent campaigns use SVG‑based attachments to run credential‑phishing pages, re‑assemble archive payloads in the browser, or launch malware after the user opens the file.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous inspection of all attachment types, not just known executable extensions.
- Highlights a gap in policy‑based controls that can be closed with evidence‑driven content‑filtering and sandboxing.
- Aligns with the control objective of preventing unauthorized code execution via email attachments, a key pillar of a robust control‑assurance program.
Who Is Affected — Organizations that rely on email for internal and external communication, especially in technology, financial services, and professional services sectors.
Recommended Actions
- Extend email attachment policies to include SVG files and enforce sandbox analysis or block by default.
- Deploy file‑based, machine‑learning detection that parses XML content for embedded scripts.
- Conduct security‑awareness training that educates users on the risks of opening unexpected image‑type attachments.
Technical Notes — SVG is an XML‑based image format; browsers parse and execute embedded <script> tags. Attackers leverage <foreignObject> and Blob APIs to render fake login pages or reconstruct malicious archives in memory. The technique bypasses traditional executable‑blocking rules because the file extension is not on default block lists. Source: Broadcom Symantec Blog