The Evil MSI Background is Back!, (Fri, Jun 5th)

2026-06-07T19:23:48Z4de6ec2c3dea37bd30a639b6d2958bd84a80fe573ad4fb117eb79873eb22a3b6
email-phishingimage-steganographymalicious-svgmalware-distributionmsinetsupport-ratphishingratreconnaissancesecurity-advisorysoapswagger.json-scanningthreat-trendwetransfer

What happened

SANS ISC diary entries (early June 2026) describe multiple active phishing/malware trends: a resurgence of MSI-themed backgrounds where an MSI payload is embedded inside image files (JPEG steganography) delivered via WeTransfer links; a spike in phishing emails delivering malicious SVG files (no visible links, image-based payload delivery); and an observed unidentified RAT that drops/pushes the NetSupport RAT. The feed also notes continued scanning for swagger.json endpoints and legacy SOAP/web-service issues. No specific CVEs are mentioned; these are active threat techniques and campaign-traw

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
4de6ec2c3dea37bd30a639b6d2958bd84a80fe573ad4fb117eb79873eb22a3b6
Enrichment time
2026-06-07T19:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.