The Image That Isn't—Stopping SVG-Borne Attacks

What security teams need to know about the latest wave of SVG attacks

  • SVG files can carry executable content, giving attackers a way to hide phishing and malware delivery inside something that looks like an image. 
  • Recent campaigns show SVG attacks spanning high-volume credential phishing, archive smuggling, and targeted malware delivery. 
  • Symantec uses file-based, machine learning, email, and web protection to stop the attack chain at multiple points. 

Multiple attackers have moved their first stage into image files. One format of choice is SVG, which email policy treats as harmless on its extension alone. But SVG is made up of XML, not pixels, making the browser parse and execute it. A single file can carry <script>, paint a convincing full-screen login page, and pass filters written for executables and archives. That combination has put SVG among the top three most common malicious attachment types. Our own telemetry shows the format going quiet through the first half of 2026 before returning sharply in August. This highlight covers why the format is trending, what we observe in the field, and how Symantec file-based, machine learning, email and web protections break the chain through to the destination.

Why SVG, and why now? 

Portable Executable is the Windows format for compiled binaries: .exe, .dll, and .sys. Non-PE is everything else: .pdf, .docx, .vbs, .js, .html, and .svg. That distinction decides which inspection path a file takes. Usually, attachment policy grows around compiled executables, macro-bearing documents, and standalone scripts. 

Script extensions make the point: .js, .vbs, .hta, and .ps1 sit on the default blocked-attachment lists of the major mail platforms, while .svg doesn’t. Microsoft narrowed the adjacent gap in late 2025 by no longer rendering inline SVG in Outlook, but when SVG gets sent as a conventional attachment it can still arrive and open in the browser. It’s the very same migration covered by the script-first highlight in this series, just one step further along. Attackers moved the first stage out of PE and into scripts, and SVG wraps the payload in something that doesn’t even present as a script.

What makes this format so weaponizable is the fact that it’s XML. A browser both parses and executes it, rather than decoding it as a bitmap. Since it carries <script> natively,a double-clicked attachment can execute as a local page. Referenced through <img src> it’s inert, and exactly why every lure pushes the user to open the file. 

That execution context gets used in three ways. A viewport-sized root with position:fixed, plus <foreignObject> for arbitrary HTML, renders a convincing login form or document viewer. A Blob can reassemble an archive in browser memory and hand it to the user as a download. It’s either the same smuggling technique long seen in HTML attachments, carried in something that presents as an image. Or the script does nothing but navigate, sending the victim to external infrastructure. Whichever it is, the harvest page, the reconstructed archive or the redirect lives inside the file. That means the message body doesn’t need to carry a URL for a gateway to reputation-check before delivery at all. 

Underneath all of it, there’s a mismatch: policy classifies .svg as an image, while the browser executes it as a document. Campaigns have pushed that further by declaring text/plain on SVG attachments to defeat content-type routing, all the while a double-click still hands the file to the browser. Obfuscation isn’t even a constant. Some samples carry nothing but a single plaintext redirect line. There’s no encoding, no decoy, no junk padding. Nothing for a classifier to reason over and nothing to deobfuscate.

  • Public reporting across 2025 and 2026 tells a consistent story about the scale and growth of SVG attacks:Microsoft observed a three-day SVG campaign, 23–25 February of 2026, delivering 1.2 million messages to 53,000+ organizations across 23 countries. The campaign used a CAPTCHA gate, followed by a fake sign-in page.
  • Hoxhunt reported roughly a fiftyfold increase in malicious SVG attachments year over year, putting SVG at about 5% of all malicious attachments and into the top three attachment types, ahead of .docx and .eml.
  • KnowBe4 noted a separate 245% increase in SVG files concealing phishing payloads.
  • INKY, part of Kaseya, reported sustained commodity volume with a voicemail-themed campaign accounting for some 26,500 detections across 5,500 organizations between June and August of 2026.

Attackers have also commoditized the build. Smuggling generators produce per-sample junk elements, randomized identifiers, and layered encoding, so the output is structurally identical and byte-wise unique. That’s precisely the condition under which hash and string signatures degrade and machine learning wins.

Campaigns' modus operandi

Every SVG chain we observed fits one skeleton. The first stages are identical whether the end goal is a stolen password or malware, making the attachment itself an important part of detection, before behavior appears further down the chain. The execute stage covers the full range: The script may be layered in obfuscation, or a single plaintext redirect line with nothing to unpack.

Two stages vary. The gate (S3g) can use CAPTCHA, geofencing, a user-agent, or an OS check as a decoy to anything that doesn’t look like the intended victim. That can defeat analysis more often than detection, with an endpoint written up as unresolved often existing and simply refusing to serve. The script stager (S5) may run two or three hops deep, get skipped entirely, or replace the compiled loader altogether. It’s also where the chain first becomes visible to endpoint telemetry, since every hop is a LOLBin execution. 

The Image That Isn't—Stopping SVG-Borne Attacks

Block telemetry over the past 12 months

Symantec blocked 222,226 SVG-attributed detections between September 2025 and September 2026. That figure counts only the signatures listed below. Generic detections such as Scr.Malcode!gen, Phish.HTML, and Web.Reputation caught substantial additional volume, but they don’t all distinguish SVG from other Non-PE carriers. The real total is meaningfully higher. As such, every figure here should be read as a floor, not a ceiling. What really matters here is the shape it presents us with: A sustained decline through the first half of the period, followed by an abrupt return to volume in August.

A long decline, from a peak of 27,443 detections in October 2025 to a trough of 10,909 in June 2026, we see a 60% fall across eight months. Then, an abrupt resurgence with August 2026 reaching 26,433, almost double the preceding six-month average of 13,496 and 142% above the June trough. It was the highest month of the period bar one, within 4% of the October peak. 

This wasn’t a single spike, either. The first half of September 2026 recorded 9,659 detections, a rate roughly 70% above the June and July average. The window opens and closes mid-month, so both September buckets cover half a month and aren’t comparable to the rest.

The decline, while consistent with format rotation, doesn’t point to the threat receding. Microsoft observed SVG volume falling 32% in March 2026 as operators moved between attachment types over the same window. Our curve tracks that pattern, suggesting the H1 dip reflects attackers cycling between formats rather than losing interest in the technique.

The Image That Isn't—Stopping SVG-Borne Attacks

Victimology

Global commodity credential phishing, that’s where the main brunt of volume is. Broad spray, no regional concentration, workplace-generic lures. That includes HR and salary reviews, DocuSign, Microsoft alerts, invoices, and voicemail with the US, UK, and Netherlands accounting for 82% of all detections. 

As for LATAM’s malware delivery, we’ve observed smaller volumes with a higher impact. The regionally targeted chains cluster in Latin America, usually within Colombia. Judicial and tax-authority lures delivering commodity RATs and stealers, such as AsyncRAT, Remcos, and DCRat in the documented cases, into a region with a firmly established financial-malware ecosystem. 

The Image That Isn't—Stopping SVG-Borne Attacks

How Symantec covers the threat 

SVG-borne attacks are engineered specifically against static detection. Every specimen is structurally identical and byte-wise unique, the malicious fraction is a rounding error against the file size, and the payload only assembles itself at parse time. No single technology closes that gap cleanly. That in itself makes the case for defense in depth rather than a caveat about it.

File-based signatures catch known campaign structures and give fast, high-confidence convictions on the bulk of commodity volume. Machine learning classification through xSenseNet handles the tail, and where Non-PE framing has a marked advantage. The deep-learning scanner was purpose-built for scripts, markup, and containerized formats where the active code sits inside something presenting as a document or an image. 

A weaponized SVG sits directly within XSenseNet’s classification scope. Its analysis of structure and content, rather than bytes alone, means per-sample randomization of junk elements and identifier names don’t move the classification. Email-layer protection blocks at delivery, before the user can open the attachment at all at the earliest and cheapest point in the chain. Web and URL protection covers the second hop when the first two are bypassed, because the redirect target is typically a shortener fronting infrastructure that rotates far faster than any attachment does. For the plaintext-redirect variant, web protection isn’t backstop but the primary control. A file that carries one line and no obfuscation gives a classifier almost nothing to weigh, so conviction rests on the destination rather than the file, and the Global Intelligence Network categorizes that destination in real time across WebPulse-enabled products.

The same chain-breaking framing carries straight over from the script-first highlight. Here, the SVG is the first stage., so stopping it at the attachments prevents the stager, the loader, the RAT, and the credential post, well before any of it reaches the endpoint.

Symantec protects you from this threat, identified by the following:

Email-based

  • Coverage is in place for Symantec's email security products and Email Threat Isolation (ETI) technology provides an extra layer of protection for our customers.

Carbon Black-based

  • Associated malicious indicators are blocked and detected by existing policies within Carbon Black products. The recommended policy at a minimum is to block all types of malware from executing (Known, Suspect, and PUP) as well as delay execution for cloud scan to get maximum benefit from Carbon Black Cloud reputation service.

File-based

  • Phish.Svg!gen2
  • Scr.MalSvg!gen1
  • Scr.MalSvg!gen2
  • Scr.MalSvg!gen3
  • Scr.MalSvg!gen4
  • Scr.MalSvg!gen5

Machine Learning-based

  • XSNet.Svg!gen1
  • XSNet.Svg!gen2

Web-based

  • Observed domains/IPs are covered under security categories in all WebPulse enabled products. 

You might also enjoy

Upcoming Events

See what's next

Threat Updates

Get the latest