New Wave Of Phishing Emails with SVG Files, (Tue, Jun 2nd)

2026-06-02T13:23:47Zcf6296d690bf9952bf674779201efc6edcb038b8b074dc84c21cc8c4e56989b9
AkiraDShieldNetSupport RATRATSVGYARA-Xevasionforensicsmalicious-attachmentsmalspamphishingransomwaretelemetry

What happened

SANS Internet Storm Center observed a surge of phishing emails delivering SVG attachments that act as the sole malicious payload (no URLs in message bodies), a technique likely used to evade link-based detection and deliver embedded/external-scripted content. The feed also includes related notes: an unidentified RAT distributing NetSupport RAT, a forensic reconstruction of an Akira ransomware kill chain, and tooling/telemetry updates (YARA‑X release, DShield upload analysis). No CVEs are referenced.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
cf6296d690bf9952bf674779201efc6edcb038b8b074dc84c21cc8c4e56989b9
Enrichment time
2026-06-02T13:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · New Wave Of Phishing Emails with SVG Files, (Tue, Jun 2nd) · Baitaphish