{"id":6678,"date":"2025-09-05T10:04:08","date_gmt":"2025-09-05T10:04:08","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/05\/colombian-malware-weaponizing-swf-and-svg-to-bypass-detection\/"},"modified":"2025-09-05T10:04:08","modified_gmt":"2025-09-05T10:04:08","slug":"colombian-malware-weaponizing-swf-and-svg-to-bypass-detection","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/05\/colombian-malware-weaponizing-swf-and-svg-to-bypass-detection\/","title":{"rendered":"Colombian Malware Weaponizing SWF and SVG to Bypass Detection"},"content":{"rendered":"<p>    Colombian Malware Weaponizing SWF and SVG to Bypass Detection<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A previously unseen malware campaign began circulating in early August 2025, through email attachments and web downloads, targeting users in Colombia and beyond.<\/p>\n<p>By leveraging two distinct vector-based file formats\u2014Adobe Flash SWF and Scalable Vector Graphics (SVG)\u2014the attackers crafted a multiphase operation that evaded traditional antivirus detection.<\/p>\n<p>Initial reports surfaced when a benign-looking SWF file named <code>Sequester.swf<\/code> triggered alerts in only a handful of antivirus engines, prompting deeper investigation.<\/p>\n<p>Within days, a companion SVG file emerged, embedding sophisticated JavaScript payloads designed to impersonate the Colombian Fiscal\u00eda General de la Naci\u00f3n portal.<\/p>\n<p>The seamless pivot between legacy and modern formats caught many security teams off guard.<\/p>\n<p>The SWF component masqueraded as a legitimate 3D puzzle game, complete with ActionScript modules for rendering, pathfinding, and cryptographic routines.<\/p>\n<p>While <a href=\"https:\/\/cybersecuritynews.com\/understanding-false-positives-in-antivirus-software\/\" target=\"_blank\" rel=\"noreferrer noopener\">antivirus engines<\/a> flagged obfuscated classes and AES routines, they failed to recognize that this code served legitimate game mechanics rather than malicious behavior.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEin57WWY1itC7YjMGFZ3CVIN_JBVXMRCti9n9K_Jx38Oy-4gTDi6_eoGCOzc6rDmj5oyM8JLOw1OLskzb7tkZJpxX0187NgoexizlVUY-RxsuIunjj4IPNtRA3X5dm-IRSl8FuxINCuW2_OqkqzRgWaEuPkbut6MQNXO10ooAi8l0ZXMQ1w-JSQvr3Wwxg\/s16000\/Malicious%2520file%2520%28Source%2520-%2520VirusTotal%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Malicious file (Source \u2013 VirusTotal)<\/figcaption><\/figure>\n<\/div>\n<p>Meanwhile, the SVG variant contained inline JavaScript that decoded a Base64 phishing page and silently dropped a ZIP archive containing additional payloads.<\/p>\n<p>The combination of these two vectors created a multiheaded threat that slipped past detection barriers with alarming ease.<\/p>\n<p>VirusTotal analysts <a href=\"https:\/\/blog.virustotal.com\/2025\/09\/uncovering-colombian-malware-campaign.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that upon expanding support for SWF and SVG analysis in Code Insight, they were able to uncover dozens of related samples within hours of the initial submissions. <\/p>\n<p>By searching for Spanish-language comments left by the attackers\u2014strings such as <code>\"POLIFORMISMO_MASIVO_SEGURO\"<\/code> and <code>\"Funciones dummy MASIVAS\"<\/code>\u2014researchers identified a cohesive campaign spanning more than 40 unique SVG files, none of which had raised flags in standard antivirus scans.<\/p>\n<p>The early presence of these markers allowed rapid signature creation and retrohunt jobs, yielding over 500 matches when applied to submissions from the previous year.<\/p>\n<p>The heart of the operation lay in its evasion tactics. By distributing large, <a href=\"https:\/\/cybersecuritynews.com\/highly-obfuscated-net-sectoprat\/\" target=\"_blank\" rel=\"noreferrer noopener\">obfuscated<\/a> SWF files that blended game code with encryption routines, the attackers exploited heuristic thresholds.<\/p>\n<p>At the same time, the SVG files embedded encrypted <a href=\"https:\/\/cybersecuritynews.com\/javascript-attacks-targeting\/\" target=\"_blank\" rel=\"noreferrer noopener\">JavaScript<\/a> in CDATA sections, evading simple pattern matching.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi20os_qFAMp2ZOKWRWH3kdVAic6iE9PUTTXBJ1GsFBuW4Wmv5YxC8yd86YUzzY5Qo-cKAsjTKqm6EVLfj3LF_PS26s5Pr7BsI-LSN3d48N3mYuwfoxs6F-7esBE5wxT0mxoQb9suOW37pCQsesYURUpSYMWsgpA-yPSMngVkmpMMqm7oih26SoJFrUgHc\/s16000\/This%2520SVG%2520file%2520executes%2520an%2520embedded%2520JavaScript%2520payload%2520upon%2520rendering%2520%28Source%2520-%2520VirusTotal%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">This SVG file executes an embedded JavaScript payload upon rendering (Source \u2013 VirusTotal)<\/figcaption><\/figure>\n<\/div>\n<p>When rendered in a browser, the script would decode and inject an HTML phishing interface, complete with progress bars and authentic-looking forms that mimicked official government communications .<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-detection-evasion-techniques\"><strong>Detection Evasion Techniques<\/strong><\/h2>\n<p>Central to this campaign\u2019s success was the layering of obfuscation and polymorphism. Each SWF sample employed variable renaming, garbage code insertion, and custom packing routines to defeat static analysis.<\/p>\n<p>The following excerpt illustrates how the SVG payload concealed its primary logic within nested Base64 strings:-<\/p>\n<pre class=\"wp-block-code\"><code>\/\/ POLIFORMISMO_MASIVO_SEGURO: 2025-09-01T16:39:16.808557\nvar payload = atob(\"UE...VUM+Cg==\");\ndocument. Write(payload);<\/code><\/pre>\n<p>Meanwhile, the YARA rule crafted by VirusTotal researchers targeted the consistent Spanish comments:-<\/p>\n<pre class=\"wp-block-code\"><code>rule svg_colombian_campaign {\n    strings:\n        $c1 = \"Funciones dummy MASIVAS\"\n        $c2 = \"POLIFORMISMO_MASIVO_SEGURO\"\n    condition:\n        uint16(0) == 0x3C3F and any of ($c*)\n}<\/code><\/pre>\n<p>This rule achieved over 523 detections when retrohunted against a year\u2019s worth of submissions.<\/p>\n<p>By combining heuristic bypasses, encrypted payloads, and intentional misdirection, the attackers demonstrated a refined understanding of both legacy and modern file formats\u2014underscoring the urgent need for context-aware analysis in contemporary <a href=\"https:\/\/cybersecuritynews.com\/threat-intelligence\/\" target=\"_blank\" rel=\"noreferrer noopener\">threat defense<\/a>.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/colombian-malware-weaponizing-swf-and-svg\/\">Colombian Malware Weaponizing SWF and SVG to Bypass Detection<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/colombian-malware-weaponizing-swf-and-svg\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Colombian Malware Weaponizing SWF and SVG to Bypass Detection A previously unseen malware campaign began circulating in early August 2025, through email attachments and web downloads, targeting users in Colombia and beyond. By leveraging two distinct vector-based file formats\u2014Adobe Flash SWF and Scalable Vector Graphics (SVG)\u2014the attackers crafted a multiphase operation that evaded traditional antivirus [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6678","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6678"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6678"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6678\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6678"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6678"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6678"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}