BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

SVG Files Used in New Colombian Phishing Campaign Bypass Antivirus

Phishing Attacks Leverage SVG Files and macOS Malware to Bypass Security in Evolving Cybercrime Campaigns

  • Researchers discovered phishing attacks using SVG files to mimic Colombia‘s judicial system.
  • Obfuscated SVG files delivered JavaScript-based payloads, leading to undetected phishing pages and hidden downloads.
  • Over 523 malicious SVG files appeared since August 2025, with evolving payload sizes indicating shifting tactics.
  • Attackers also target macOS users with Atomic macOS Stealer (AMOS), using cracked software sites and terminal commands.
  • Security updates in macOS Sequoia have blocked some attack attempts, but attackers now use new techniques to bypass safeguards.

Cybersecurity experts have reported a wave of phishing campaigns that exploit SVG image files to target users, mainly by pretending to represent the Colombian judicial system. Attackers distribute these SVG files in email attachments, using them to trick recipients into revealing sensitive information.

- Advertisement -

According to VirusTotal, the SVG files contain hidden JavaScript code that injects a fake HTML page imitating the official portal of the Fiscalía General de la Nación, or the Attorney General’s Office in Colombia. This phishing page acts like a government document download service with a fake progress bar. In the background, it downloads a ZIP archive, whose contents remain undisclosed.

The Google-owned security service identified forty-four unique SVG files that evaded antivirus detection through obfuscation, polymorphism (constant changes in the file’s structure), and junk code. In total, researchers found 523 samples of these malicious SVG files as of August 2025. “Looking deeper, we saw that the earliest samples were larger, around 25 MB, and the size decreased over time, suggesting the attackers were evolving their payloads,” VirusTotal stated in its Malware-campaign.html”>report.

At the same time, macOS systems face threats from the Atomic macOS Stealer (AMOS). Attackers lure users looking for cracked apps on sites like haxmac[.]cc, then redirect them to instructions that convince victims to run commands in the Terminal app. These commands deploy AMOS, which can steal credentials, browser information, cryptocurrency wallets, messaging data, VPN settings, and files. Trend Micro noted, “AMOS shows that macOS is no longer a peripheral target.” The company explained that new macOS security requirements, such as Gatekeeper and app notarization, have blocked some attacks but have not stopped Hackers from shifting to command-line delivery methods.

Security updates with macOS Sequoia have made installation of unsigned and malicious .dmg application files more difficult. However, “threat actors quickly pivoted to terminal-based installation methods that proved more effective in bypassing security controls,” Trend Micro reported in their analysis.

- Advertisement -

In a separate campaign, researchers from CyberArk found criminals targeting gamers searching for cheats with malware like StealC and crypto-stealing tools. This operation allegedly netted attackers over $135,000 by pulling digital currency from infected systems. For more details, see CyberArk’s research.

Attackers continue to adapt, using new methods to bypass improved security and maximize stolen data.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Trump-Backed Crypto Token WLFI Plummets to Record Low

The World Liberty Financial token WLFI plunged to an all-time low, dropping 83% from...

Global Police Use Ad-Based Phone Tracking

An ad-based surveillance tool, Webloc, is used by global law enforcement to track up...

Suspect Arrested After Molotov Cocktail Attack on OpenAI CEO’s Home

A suspect allegedly threw a Molotov cocktail at the home of OpenAI CEO Sam...

Suspect Attacks OpenAI CEO Sam Altman’s Home With Molotov Cocktail

OpenAI CEO Sam Altman's San Francisco home was targeted with a Molotov cocktail early...

Justin Sun’s $70M Frozen in Trump-Linked Crypto Project

Justin Sun had approximately 544 million World Liberty Financial tokens frozen in September 2024...

Must Read

5 Best Crypto Jobs Sites To Land Your Next Six Figure Job

The cryptocurrency and blockchain job market has exploded. With new blockchain start-ups and projects being founded at a blistering pace, the demand for workers...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading