The Evil MSI Background is Back!, (Fri, Jun 5th)
2026-06-06T07:23:44Z•a6a071f50b595912a9bd9bae3eea35bfc8c4908ac8605fe86bb5ade031397c8a
JPEG steganographyNetSupport RATRATSVGapi-exposureimage-based payloadmalicious SVGmalwarephishingreconnaissanceswagger.jsonthreat-trendwe-transfer
What happened
SANS ISC diary entries (early June 2026) describe several active attack trends: a resurgence of a payload embedded in a JPEG (MSI-branded background) distributed via WeTransfer links; a spike in phishing emails delivering malicious SVG files (image-only delivery to evade URL detection); ongoing scans for publicly exposed swagger.json files (risk of leaked API endpoints/credentials); and a report of an unidentified RAT that installs NetSupport RAT. These items indicate growing use of image-based delivery/steganography and increased reconnaissance of API surfaces, with ongoing commodity RATs in
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- a6a071f50b595912a9bd9bae3eea35bfc8c4908ac8605fe86bb5ade031397c8a
- Enrichment time
- 2026-06-06T07:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.