Cybercriminals Weaponize SVG Files to Deliver AsyncRAT Malware in Latin America
A recent malware campaign targeting users in Latin America, particularly Colombia, demonstrates the evolving tactics of cybercriminals who are weaponizing Scalable Vector Graphics (SVG) files. These attacks utilize social engineering, sending emails that mimic trusted institutions with urgent warnings about lawsuits or court summons to induce victims into opening malicious attachments. Unlike traditional methods, this campaign employs oversized SVG files containing embedded scripts and interactive elements, a technique known as SVG smuggling. This approach allows the file to render a fake judicial portal within the web browser, creating an illusion of authenticity while bypassing some security detections. Upon interaction, the SVG triggers the download of a password-protected ZIP archive containing an executable. This final payload installs AsyncRAT, a remote access trojan capable of keystroke logging, screen capturing, and credential theft. Notably, the campaign leverages artificial intelligence to generate customized files for targets and uses DLL sideloading to further compromise devices. This method eliminates the need for external connections to command-and-control servers during the initial stages, making the attack more stealthy and difficult to detect by traditional security tools.
Wire timeline
Cybercriminals Weaponize SVG Files to Deliver AsyncRAT Malware in Latin America
A recent malware campaign targeting users in Latin America, particularly Colombia, demonstrates the evolving tactics of cybercriminals who are weaponizing Scalable Vector Graphics (SVG) files. These attacks utilize social engineering, sending emails that mimic trusted institutions with urgent warnings about lawsuits or court summons to induce victims into opening malicious attachments. Unlike traditional methods, this campaign employs oversized SVG files containing embedded scripts and interactive elements, a technique known as SVG smuggling. This approach allows the file to render a fake judicial portal within the web browser, creating an illusion of authenticity while bypassing some security detections. Upon interaction, the SVG triggers the download of a password-protected ZIP archive containing an executable. This final payload installs AsyncRAT, a remote access trojan capable of keystroke logging, screen capturing, and credential theft. Notably, the campaign leverages artificial intelligence to generate customized files for targets and uses DLL sideloading to further compromise devices. This method eliminates the need for external connections to command-and-control servers during the initial stages, making the attack more stealthy and difficult to detect by traditional security tools.
WeLiveSecurity