isc.sans.edu 6/2/2026, 9:21:14 AM · external

SVG Phishing Emails Use Base64 JavaScript to Redirect Users

SVG Phishing Emails Use Base64 JavaScript to Redirect Users
CyberSIXT Evidence Panel Source marked as original reporting

XAVIER Mertens reports a recent surge in phishing emails that utilize SVG files to deliver malicious content. These SVG files, while simplistic and lacking graphical elements, contain JavaScript designed to redirect victims to phishing sites. The payload is obscured through Base64 encoding and XOR operations, leveraging a cheap TLD ('.cfd') commonly abused in phishing campaigns. Mertens notes that SVG files are handled by default on Windows browsers, providing an avenue for such attacks.

The email alerts a targeted address which, combined with an unusual MIME type declaration ('application/ecmascript'), may try to evade common security filters. This method exemplifies a new wave of phishing threats.

View full article

Article by CyberSIXT