A File Type Nobody Thinks Twice About
Here's the thing about file-type trust: most security teams have hardened their perimeters against .exe and .zip attachments, but SVG files? Nobody flags those. They're images. They render in your browser like a .png would. Except SVGs are also XML documents that can contain JavaScript, and attackers figured that out before most defenders did.
VirusTotal researchers discovered an active phishing campaign that weaponizes SVG files as full-blown phishing portals impersonating Colombia's judicial system. The operation was first detected on June 9, 2025, and VirusTotal only published their analysis on September 5, 2025 — a deliberate delay to give organizations time to respond while the campaign was still active.
This isn't some corner-of-the-internet trick targeting individual users. It's a structured social engineering operation that turns a mundane image format into an interactive portal, harvests credentials, and delivers remote access malware. And it slipped through because nobody thought to block it.
How the SVG Phishing Attack Actually Works
The attack chain is deceptively straightforward.
The initial lure is a message — email or messaging app — containing an SVG attachment or a link to an SVG file hosted on GitHub. When the victim opens that SVG, their browser renders it as a live document, not a static image. Embedded JavaScript executes in the browser context. Suddenly, instead of looking at a picture, the victim is staring at a convincing interactive webpage that mimics Colombia's judicial system interface.
From that rendered portal, the user is directed to a GitHub Pages site hosting a fake judicial portal. Same look, same feel, same language. They're prompted to download what appears to be a legal document.
That "document" is an MSI installer. And the installer drops one of three known malware families: Amadey, Vidar, or RedLine. These aren't exotic tools — they're commodity stealers and botnets widely available on underground forums. Their job is credential harvesting, data exfiltration, and providing a foothold for follow-on attacks. If those names sound familiar, they should: the same infostealer ecosystem that quietly drains browser credentials feeds directly into this kind of campaign.
The elegance here is the abuse of trust boundaries. SVG gets past email filters because it's an image format. GitHub gets past URL reputation systems because it's a legitimate developer platform. The browser executes the JavaScript because SVG supports embedded scripts by design. Each hop is technically legitimate on its own. Together, they form a kill chain.
VirusTotal's AI Code Insight and the Detection Challenge
What makes this campaign notable isn't just the technique — it's how it was caught.
VirusTotal's AI Code Insight feature, which generates automated explanations of file behavior and dissections of code, was the tool that let analysts quickly unpack what the SVG files were actually doing. Without it, an analyst staring at an SVG with embedded JavaScript would need to manually trace through the script, understand the redirect logic, and connect it to the downstream GitHub Pages infrastructure. AI Code Insight compressed that into a working context the analyst could evaluate and validate.
The timing of the disclosure also deserves attention. VirusTotal found the campaign in June but waited until September to publish. That's a three-month window where threat intel teams were aware of the campaign while the broader security community wasn't. The reasoning is sound, early disclosure tips off attackers and gives them time to rotate infrastructure before defenders can deploy detections. But it also means that for those three months, most endpoint protections had zero signature or behavioral guidance specific to this SVG-based vector.
The campaign uses the domain ramajudicial[.]site, which is a typosquat of Colombia's legitimate judicial system web presence. The infrastructure relies on GitHub accounts for both SVG hosting and GitHub Pages for the fake portal landing pages. That's a pattern worth remembering: when attackers lean on trusted platforms for hosting, takedown requests become the primary mitigation, and takedown takes time.
Why This Matters for Critical Infrastructure Defenders
Colombia's judicial system isn't a random target. Legal and government entities in Latin America are known hunting grounds for both financially motivated operators and state-aligned groups. The campaign's malware choices, Amadey, Vidar, RedLine, all have command-and-control infrastructure that overlaps with a wide range of criminal operations. You're not just stealing a judge's password. You're potentially opening a path into a government network.
CISA's guidance on critical infrastructure protection emphasizes layered defenses and the principle that no single control is sufficient, the same reasoning behind recent joint critical infrastructure cyber resilience guidance from CISA and its international partners. This campaign is a textbook illustration of that principle. An email gateway that blocks attachments by extension catches nothing if the attacker switches from .zip to .svg. A URL filter that blocks known-bad domains catches nothing if the SVG lives on GitHub. A browser that blocks JavaScript execution on untrusted sites catches nothing if SVG rendering is treated as a trusted document type.
VirusTotal confirmed that organizations in Colombia and Peru were targeted. That geographic concentration suggests a campaign with specific intelligence about its targets, not spray-and-pray phishing.
Defensive Lessons From This Campaign
Three takeaways stand out.
First, file-type reputation is a losing game. If your email security posture depends on blocking a specific set of extensions, you've already lost. Attackers don't pick file types for functionality, they pick them for trust. SVG is now the example, but the list of formats with embedded scripting capability is long. What works is content analysis that looks at what the file does, not what its extension claims.
Second, developer platform abuse is a live threat vector that most security policies don't address. GitHub, GitLab, CodePen, these platforms host content with full browser rendering capability. Blocking them entirely is impractical for organizations with developer staff. But restricting browser execution of JavaScript from these domains for non-developer user groups? That's feasible, and it would have killed this campaign's SVG rendering step cold.
Third, AI-assisted analysis isn't a replacement for human judgment but it changes the math. VirusTotal's AI Code Insight didn't catch this campaign on its own, researchers still had to validate the output, trace the infrastructure, and decide the campaign was worth publishing. What it did was make that validation fast enough that a mid-size team could do it in days rather than weeks. In an environment where adversary infrastructure rotates weekly, that speed matters.
For defenders building out their detection engineering roadmap, the broader lesson is that phishing campaigns are no longer content-bound. They're context-bound. The SVG itself is blank canvas, the threat only materializes when rendered in a browser with JavaScript execution enabled. That means detection logic needs to run at render time, not at ingest time. Which is a hard problem. And one that organizations with mature AI cybersecurity threat detection programs are already working on.
The Bigger Picture on Phishing Evolution
This campaign didn't emerge in isolation. It's part of a broader pattern where phishing operators are migrating away from traditional email attachments toward hosted content that renders in-browser, ClickFix lures that paste commands into the terminal, hosted fake portals that use legitimate CDN infrastructure, and now SVG-based interactive documents. Campaigns are even fingerprinting visitors to serve device-specific malware through the same phishing link. Each step pushes the point of detection further from the email gateway and closer to the endpoint.
The malware families involved, Amadey, Vidar, RedLine, are the same commodity tools that fuel ransomware precursor operations, initial-access sales, and infostealer ecosystems. When a phishing campaign drops one of these, the risk isn't just the single compromised host. It's what happens next. The stolen credentials get sold, resold, and eventually used by operators with entirely different objectives than the initial phishing group.
VirusTotal's analysis is public now, and the IOCs are available for detection engineering. The question for every organization is whether you were already exposed during that June-to-September window, and whether your current controls would catch a variant that swaps GitHub for another trusted host.