Loading cryptocurrency prices...

Malicious SVG Files Used in Phishing to Spread Crypto Malware

Sophisticated Phishing Campaign Targets Ukraine with Fileless Malware and Cryptocurrency Miners

  • Attackers use phishing emails pretending to be Ukrainian government agencies to deliver Malware.
  • Malicious SVG attachments start a download chain leading to remote access trojans and cryptocurrency mining tools.
  • The main malware involved are CountLoader, Amatera Stealer, and PureMiner, with CountLoader acting as a delivery tool.
  • Malware is developed and spread by a group known as PureCoder, offering products like PureRAT and PureMiner.
  • Researchers highlight growing sophistication in these attacks, including fileless malware that evades detection.

On September 26, 2025, researchers identified a phishing campaign targeting Ukrainian government agencies. Attackers sent emails mimicking official messages from the National Police of Ukraine. The aim was to infect systems with malware used to steal data and mine cryptocurrency.

- Advertisement -

According to a report by Fortinet FortiGuard Labs, the emails contained malicious SVG (Scalable Vector Graphics) attachments. When opened, these files downloaded a password-protected ZIP archive. The ZIP included a Compiled HTML Help (CHM) file, which, when activated, triggered a series of steps leading to the deployment of the CountLoader malware.

CountLoader then delivered two main threats: Amatera Stealer, designed to steal information, and PureMiner, used for illegal cryptocurrency mining. The same campaign used various tools linked to a developer known as PureCoder, who also created malware like PureRAT, PureHVNC RAT, and PureClipper, among others. These programs can allow remote control of infected devices, steal saved information, or redirect cryptocurrency transactions.

Researchers noted that both Amatera Stealer and PureMiner operate as fileless malware, meaning they run without leaving files on a computer’s hard drive. Instead, they execute directly in a computer’s memory. The process involves techniques like .NET Ahead-of-Time (AOT) compilation and process hollowing, or are loaded into memory using Python-based tools.

Amatera Stealer looks for certain files and collects data from popular web browsers and applications like Steam, Telegram, and FileZilla, as well as various cryptocurrency wallets. “This phishing campaign demonstrates how a malicious SVG file can act as an HTML substitute to initiate an infection chain,” Fortinet said. The SVG code led users to a site that triggered further downloads.

- Advertisement -

In a related development, security firm Huntress discovered a group likely based in Vietnam using similar phishing methods targeting recipients with supposed copyright notices. This campaign also used ZIP files, which installed PXA Stealer and eventually PureRAT through several layers of hidden loaders and credential theft.

“This campaign demonstrates a clear and deliberate progression, starting with a simple phishing lure and escalating through layers of in-memory loaders, defense evasion, and credential theft,” said security researcher James Northey in his report. The attacks show a move from basic techniques to more advanced methods using modular, commercial malware.

For further details, see the full Fortinet FortiGuard Labs report.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Venezuela Deepens Stablecoin Use Amid US Tensions and Inflation Crisis

Increasing U.S. military presence near Venezuela raises fears of conflict amid accusations of drug...

Gate Launches Full Web3 Ecosystem with New Wallet, DEX & Travel

Gate is shifting to an “All in Web3” approach to become a comprehensive Web3...

S&P Rates Michael Saylor’s Strategy “B-” with Stable Outlook

Strategy, a company with significant Bitcoin holdings, received a “B-” credit rating in the...

Amazon (AMZN) to Lay Off 30,000 Workers Beginning October 28

Amazon plans to lay off up to 30,000 employees starting October 28, 2025.The job...

ETHZilla sells $40M ETH to fund $250M stock buyback plan

ETHZilla sold approximately $40 million worth of ether (ETH) from its treasury on October...
- Advertisement -

Must Read

17 Best Audiobooks On Blockchain Technology For Beginners

If you're looking to dive into the world of blockchain technology, you're in for a treat. The field is rapidly evolving and the potential...