Cisco Talos has discovered that phishing campaigns using the Qakbot malware are using Scalable Vector Graphics (SVG) images embedded in HTML email attachments. This HTML smuggling technique allows attackers to evade email gateways by storing binary code as JavaScript that is decoded and downloaded when opened via a web browser. The malicious code is executed when the victim opens the HTML attachment from the email, causing a ZIP archive to be created and an ISO image to be extracted to run the Qakbot trojan. Read more: https://thehackernews.com/2022/12/hacking-using-svg-files-to-smuggle-qbot.html
1 comment
That's some "Inception" level stuff.