News

It’s worth noting that the use of SVG files inside HTML containing base64-obfuscated code isn’t new. The same technique was observed in malspam delivering Qbot malware in December 2022.
Unlike raster image types, such as JPG and PNG files, SVGs are XML-based vector images that can include HTML <script> tags, which is a legitimate feature of that file format.
A vector file is an image that can be made infinitely large without losing quality, and usually comes as an .AI, .EPS, .PDF, or .SVG file.