The Evil MSI Background is Back!, (Fri, Jun 5th)
2026-06-06T01:23:46Z•aef0785f835bf53d539f2ec44b9c791761afaba28d676b2c8e1841a3f2793990
api-scanningcoreutilsgnuwin32jpeg-embedded-payloadmalwaremsinetsupport-ratphishingratsans-iscsoapsteganographysvgswagger.jsonwe-transfer
What happened
SANS ISC diary entries (early June 2026) report several active phishing and malware trends: a revived technique embedding payloads (MSI-branded background) into JPEGs delivered via WeTransfer links; a surge of phishing emails delivering malicious SVG files; and an unidentified RAT that deploys NetSupport RAT. Other items include ongoing scans for swagger.json endpoints (API surface discovery) and a note about Microsoft/CoreUtils for Windows. No specific CVEs are referenced in these entries.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- aef0785f835bf53d539f2ec44b9c791761afaba28d676b2c8e1841a3f2793990
- Enrichment time
- 2026-06-06T01:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.