The Evil MSI Background is Back!, (Fri, Jun 5th)
2026-06-07T19:23:48Z•4de6ec2c3dea37bd30a639b6d2958bd84a80fe573ad4fb117eb79873eb22a3b6
email-phishingimage-steganographymalicious-svgmalware-distributionmsinetsupport-ratphishingratreconnaissancesecurity-advisorysoapswagger.json-scanningthreat-trendwetransfer
What happened
SANS ISC diary entries (early June 2026) describe multiple active phishing/malware trends: a resurgence of MSI-themed backgrounds where an MSI payload is embedded inside image files (JPEG steganography) delivered via WeTransfer links; a spike in phishing emails delivering malicious SVG files (no visible links, image-based payload delivery); and an observed unidentified RAT that drops/pushes the NetSupport RAT. The feed also notes continued scanning for swagger.json endpoints and legacy SOAP/web-service issues. No specific CVEs are mentioned; these are active threat techniques and campaign-traw
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 4de6ec2c3dea37bd30a639b6d2958bd84a80fe573ad4fb117eb79873eb22a3b6
- Enrichment time
- 2026-06-07T19:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.