New Wave Of Phishing Emails with SVG Files, (Tue, Jun 2nd)

2026-06-03T01:23:45Z784d03bb4025939bf936aeb69b78d41c5d3461b0c22fd4c3775e2c1e38a8a9b9
akiraattachmentsdshieldfirewall-logsforensicslog-correlationmalspamnetSupport RATphishingransomwareratremote access trojansvgtelemetrythreat-huntingwindows-event-logsyara-x

What happened

SANS ISC reports a recent spike in malspam delivering weaponized SVG image files (no URLs in body) used to deliver malicious content. Other posts describe an unidentified RAT dropping NetSupport RAT, an in-depth Akira ransomware kill‑chain reconstruction (emphasizing the value of joining perimeter/firewall and Windows event logs), YARA‑X 1.17.0 release (performance fixes), and DShield sensor upload/telemetry analysis. The SVG‑based phishing and active RAT/ransomware activity represent immediate operational threats; defenders should treat SVG attachments as active content, sandbox and block unv

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
784d03bb4025939bf936aeb69b78d41c5d3461b0c22fd4c3775e2c1e38a8a9b9
Enrichment time
2026-06-03T01:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.