News

Seemingly harmless SVGs are packed with malicious JavaScript for a phishing redirect to actor-controlled URLs.
Once opened in a browser, the code decrypts a secondary payload using a static XOR key and then redirects the user to an ...