DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling
Brief
A new DCRat campaign is using a familiar image format to hide a dangerous malware archive. The operation begins with phishing emails that pose as legal notifications and urge recipients to open an attached SVG file.
The attachment looks harmless because SVG files are commonly used for graphics. In this case, however, the file contains hidden code that builds and downloads a password-protected archive directly inside the victim’s browser.
Analysts at Trellix identified the campaign after investigating a customer escalation in early 2026.
The researchers found that the attackers combined social engineering, hidden browser code, DLL sideloading, and process hollowing to place DCRat inside a trusted Windows process.
DCRat malware distribution methods have also shown how attackers continue to adapt the remote-access tool for different delivery channels.
