06/18/2026
It looked like an invoice. It behaved like a threat.
WatchGuard research covered by HackRead shows how attackers linked to BianLian are using fake invoice and budget SVG images to target organizations in Venezuela.
The takeaway is simple: “safe-looking” file types are not always safe.
These SVG files are designed to appear routine, but behind the image is hidden code that can redirect victims, download malicious payloads, and help attackers move closer to ransomware impact.
For defenders, this is another reminder that phishing has evolved far beyond suspicious links and obvious attachments. Security teams need visibility into the full attack path, including the file types users are conditioned to trust.
Read the full Hackread coverage for the details and indicators to watch: https://wgrd.tech/4aGkjN3
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at