New Wave Of Phishing Emails with SVG Files, (Tue, Jun 2nd)
2026-06-02T13:23:47Z•cf6296d690bf9952bf674779201efc6edcb038b8b074dc84c21cc8c4e56989b9
AkiraDShieldNetSupport RATRATSVGYARA-Xevasionforensicsmalicious-attachmentsmalspamphishingransomwaretelemetry
What happened
SANS Internet Storm Center observed a surge of phishing emails delivering SVG attachments that act as the sole malicious payload (no URLs in message bodies), a technique likely used to evade link-based detection and deliver embedded/external-scripted content. The feed also includes related notes: an unidentified RAT distributing NetSupport RAT, a forensic reconstruction of an Akira ransomware kill chain, and tooling/telemetry updates (YARA‑X release, DShield upload analysis). No CVEs are referenced.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- cf6296d690bf9952bf674779201efc6edcb038b8b074dc84c21cc8c4e56989b9
- Enrichment time
- 2026-06-02T13:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.