Email attachment

Summary

Attackers have used malicious links embedded in files for a long time, but it remains an effective way to bypass traditional email-based phishing controls. Recently, we’ve seen attackers move away from traditional PDF attachments to use SVGs and other file formats.

More sophisticated attacks are using email attachments alongside local webpages to spawn self-contained phishing pages on the client-side.

Examples