Image: Symantec
Symantec blocked 26,433 malicious SVG files in August 2026, nearly double its six-month average. That jump marks a sharp return for SVG phishing attacks after a quiet first half of the year. In its latest analysis of SVG-borne attacks, Symantec explains why a file that looks like a picture keeps getting past email filters.
At a Glance
| Actor | Multiple unnamed cybercrime groups |
| Activity | Credential phishing and malware delivery via SVG attachments |
| Targets | Businesses worldwide; 82% of detections in the US, UK, and Netherlands |
| Scale | 222,226 Symantec detections from Sept 2025 to Sept 2026 |
| Law enforcement | No arrests or takedowns announced |
| Sources | Symantec; INKY (Kaseya); Microsoft; Hoxhunt |
TL;DR
Attackers hide login pages, redirects, and malware inside SVG image files. Symantec saw volume fall for eight months, then surge again in August 2026. The format now ranks among the top three malicious attachment types.
What Happened
An Image That Runs Code
SVG files are built from XML, not pixels. As a result, a browser parses and runs them like a web page. A single file can carry a script and paint a full-screen login form. Yet many email rules still treat .svg as a harmless image. Symantec sums up the core problem: “policy classifies .svg as an image, while the browser executes it as a document.”
Attackers use that gap in three ways. Some files draw a fake sign-in page. Others use SVG smuggling to rebuild a malicious archive in memory and hand it over as a download. Still others simply send the victim to an outside site.
Tricks to Slip Past Filters
Some campaigns label SVG attachments as plain text to fool content-type checks. INKY, part of Kaseya, tracked this trick in a voicemail-themed campaign. That wave hit 5,527 organizations with 26,589 emails between June and August 2026. Many messages even spoofed the recipient’s own domain.
Meanwhile, builder tools now generate a unique file for every send. Each copy adds random junk and new names. Therefore, hash-based signatures struggle to keep up.
Who Is Behind It
No single group owns this technique. Instead, Symantec describes a broad, commodity threat used by many crews. Neither Symantec nor INKY has attributed the recent waves to a named actor. However, Symantec did spot a regional pattern. In Latin America, and Colombia in particular, fake court and tax notices drop remote access trojans such as AsyncRAT, Remcos, and DCRat.
Impact and Scale
Symantec logged 222,226 SVG-linked detections over 12 months. Detections fell 60% from October 2025 to June 2026. Then August volume climbed 142% above the June low. The company warns that its figures are “a floor, not a ceiling,” because generic detections are not counted.
Other vendors report similar growth. For example, Microsoft saw one three-day campaign in February 2026 send 1.2 million messages to over 53,000 organizations. Hoxhunt, for its part, reported a roughly fiftyfold yearly rise in malicious SVG attachments. Symantec reads the mid-year dip as format rotation, not retreat.
How to Stay Protected
Symantec argues that no single control stops SVG phishing attacks. It recommends layered defense, including email, file, machine learning, and web protection. Security teams can also take these steps:
- Block or quarantine inbound .svg attachments unless a clear business need exists.
- Inspect file content, not just the extension or declared content type.
- Filter web traffic, since many SVG files only redirect to a phishing site.
- Tighten controls against emails that spoof your own domain.
- Train staff to distrust image attachments tied to voicemails, invoices, or HR notices.
In short, treat every SVG as active content. Stopping the file at the inbox breaks the chain before any stager, loader, or fake login page can run.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!