The Evil MSI Background is Back!, (Fri, Jun 5th)

2026-06-06T07:23:44Za6a071f50b595912a9bd9bae3eea35bfc8c4908ac8605fe86bb5ade031397c8a
JPEG steganographyNetSupport RATRATSVGapi-exposureimage-based payloadmalicious SVGmalwarephishingreconnaissanceswagger.jsonthreat-trendwe-transfer

What happened

SANS ISC diary entries (early June 2026) describe several active attack trends: a resurgence of a payload embedded in a JPEG (MSI-branded background) distributed via WeTransfer links; a spike in phishing emails delivering malicious SVG files (image-only delivery to evade URL detection); ongoing scans for publicly exposed swagger.json files (risk of leaked API endpoints/credentials); and a report of an unidentified RAT that installs NetSupport RAT. These items indicate growing use of image-based delivery/steganography and increased reconnaissance of API surfaces, with ongoing commodity RATs in

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
a6a071f50b595912a9bd9bae3eea35bfc8c4908ac8605fe86bb5ade031397c8a
Enrichment time
2026-06-06T07:23:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.