Stop treating SVG image files as harmless or be caught out in phishing attacks

Have you ever considered treating every inbound image file as an executable as part of your threat detection and response plan? Let me rephrase that question: why the heck don’t you treat every inbound image file as an executable?

Threat actors have been exploiting seemingly harmless image files as an attack strategy since, well, forever. What if I were to tell you that someone who looked a lot like me once hacked a system using a keylogger that stored everything in an image file to avoid detection by a sysadmin who didn’t know as much as they thought they did?

That was 30 years ago. Fast-forward to now and the threats have moved on to a far more sophisticated level as part of phishing attacks.

How SVG image files are being used by hackers

Researchers from Ontinue’s Advanced Threat Operations team have, this week, published details of how hackers are embedding obfuscated JavaScript within Scalable Vector Graphics (SVG) image files. The aim: to perform browser redirects to malicious sites. A phished user clicks on an image attached to the email and the work is done.

This marks an increasingly observable trend of threat actors shifting from executable payloads that are relatively easy to detect, to embedding script logic into image formats and using trusted browser functions, which are not.

The specific campaign that caught the attention of the Ontinue researchers employed browser-native redirection without requiring user interaction or external downloads and, as such, “bridges the gap between traditional phishing and full malware delivery,” the researchers said.

Why you should take notice of the SVG phishing attacks

Although the use of SVG image files in phishing attacks isn’t new, this new campaign employs new tactics worthy of your attention.

First, the attackers are delivering the SVG files by way of spoofed emails that exploit a lack of Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting, and Conformance (DMARC) controls. Or ones that are too weakly employed to be of much protection.

The emails are, the researchers said, “minimalistic to avoid suspicion and prompt users to open or preview the SVG in browsers, triggering silent script execution”.

The attackers here are relying upon complacency of the “it’s only an image, it doesn’t execute code” variety, said John Bambenek, President at Bambenek Consulting.

The hope is that this will “lull organisations into accepting this content and getting it on the inside of a network”, warned Bambenek.

“Defenders must collapse the old distinction between code and content,” said Jason Soroko, a Senior Fellow at Sectigo. In short, they must “treat every inbound SVG as a potential executable”.

That applies as much to end users as it does to enterprise security teams. The key takeaway is that what you can see can hurt you, and this is particularly true for SVG image files.

More recent articles by Davey that you should definitely read

About The Author

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.