{"success":true,"data":{"id":"svg-base64-portal","label":"SVG attachment or inline base64-encoded SVG used as a phishing portal with embedded HTML/credential-harvest content","description":"SVG file attachment or inline base64-encoded SVG (data:image/svg+xml;base64,) used as a phishing portal. SVG is uniquely dangerous as an email vector because SVG is an XML format that can contain embedded JavaScript, HTML foreignObject elements, and hyperlinks — all rendering in email clients or browsers that open SVG inline. Attackers embed a credential-harvesting HTML page inside an SVG using base64 encoding to evade signature-based attachment scanners. The SVG may appear as a company logo or document thumbnail but opens a fake login page when clicked. The signal fires when: (1) an SVG attachment is present OR inline data:image/svg+xml;base64 appears in the HTML body AND (2) a credential/account-action narrative is present (verify, sign in, open document, restore access) AND (3) sender is NOT from a known design platform (Figma, Canva, Adobe) AND (4) no List-Unsubscribe header. Source: GC1 R13 council #2; Sophos SVG phishing 2024-2025; ANY.RUN SVG-as-phishing-portal samples 2026.","tier":"warning","category":"other","isThin":false}}