New Wave Of Phishing Emails with SVG Files, (Tue, Jun 2nd)
2026-06-03T01:23:45Z•784d03bb4025939bf936aeb69b78d41c5d3461b0c22fd4c3775e2c1e38a8a9b9
akiraattachmentsdshieldfirewall-logsforensicslog-correlationmalspamnetSupport RATphishingransomwareratremote access trojansvgtelemetrythreat-huntingwindows-event-logsyara-x
What happened
SANS ISC reports a recent spike in malspam delivering weaponized SVG image files (no URLs in body) used to deliver malicious content. Other posts describe an unidentified RAT dropping NetSupport RAT, an in-depth Akira ransomware kill‑chain reconstruction (emphasizing the value of joining perimeter/firewall and Windows event logs), YARA‑X 1.17.0 release (performance fixes), and DShield sensor upload/telemetry analysis. The SVG‑based phishing and active RAT/ransomware activity represent immediate operational threats; defenders should treat SVG attachments as active content, sandbox and block unv
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 784d03bb4025939bf936aeb69b78d41c5d3461b0c22fd4c3775e2c1e38a8a9b9
- Enrichment time
- 2026-06-03T01:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.