Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Use Court-Themed Phishing to Deliver Info-Stealer Malware

A sophisticated phishing campaign has been identified, targeting users in Colombia by exploiting judicial notifications and utilizing Scalable Vector Graphics (SVG) files.

A sophisticated phishing campaign has been identified, targeting users in Colombia by exploiting judicial notifications and utilizing Scalable Vector Graphics (SVG) files.

The attack initiates with a Spanish-language email that impersonates the "17th Municipal Civil Court of the Bogotá Circuit." The email is crafted to appear legitimate, using formal legal language and institutional details.

The email includes an SVG attachment titled "Fiscalia General De La Nacion Juzgado Civil 17.svg," which leads recipients into a multi-stage infection chain. This process ultimately delivers the AsyncRAT remote access Trojan (RAT) through in-memory injection into a trusted Windows process.

The phishing email mimics an official court notice, referencing Bogotá’s municipal civil court and presenting a false notification of legal action. The SVG file contains XML-based instructions, including an onclick handler that decodes a Base64-encoded HTML blob, presenting a fake consultation portal that prompts the download of an HTA file.

Clicking "DOWNLOAD DOCUMENTO_OFICIAL_JUZGADO.HTA" executes a client-side dropper. The HTA file contains junk code and decodes a Base64 block into actualiza.vbs .

This process ultimately delivers the AsyncRAT remote access Trojan (RAT) through in-memory injection into a trusted Windows process.
Eleanor Tate · Thehackingpost

This Visual Basic script writes and runs a PowerShell downloader ( veooZ.ps1 ), which retrieves a text file from an attacker-controlled server. The script processes this file to produce classlibrary3.dll , functioning as a module loader for the AsyncRAT payload.

The loader checks for VirtualBox and VMware processes to avoid sandbox detection, but persistence methods via registry keys are disabled in this campaign.

AsyncRAT executes in memory within MSBuild.exe, gathering system details such as hardware identifiers and operating system version. It uses obfuscation and anti-analysis techniques, including AMSI bypass, to evade detection.

Advertisement

The RAT establishes a TLS-encrypted channel to its command-and-control server, supporting activities like keylogging, file management, and webcam surveillance.

Security teams are advised to monitor for unusual SVG behaviors and enforce strict email attachment policies to mitigate such threats.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories