Hackers have launched a sophisticated phishing campaign that impersonates official notices from the National Police of Ukraine to target organizations running Microsoft Windows. The campaign begins with emails containing malicious Scalable Vector Graphics (SVG) files, which are exploited due to their text-based nature that allows embedding of harmful scripts. When recipients open the SVG attachment, they are presented with a deceptive loading screen, after which the system downloads password-protected ZIP archives such as ergosystem.zip or smtpB.zip. The password is provided in the email to increase the appearance of legitimacy. Inside these archives, a Compiled HTML Help (CHM) file acts as the main trigger, executing a malicious script known as CountLoader. This loader connects to a remote server, exfiltrates basic system information, and then delivers the final malware payloads directly into memory, making detection challenging. The two primary payloads identified are Amatera Stealer, which is designed to steal sensitive data, and PureMiner, a cryptominer that hijacks system resources for illicit cryptocurrency mining. PureMiner is delivered using DLL sideloading techniques from the ZIP archive, while Amatera Stealer is deployed through the same infection chain. Security researchers have highlighted the dual threat posed by this campaign: data theft and resource hijacking. The use of SVG files is particularly concerning because they can contain embedded JavaScript and HTML, and on Windows systems, they are often opened by Microsoft Edge, which may lack adequate security controls if not the user's primary browser. The attackers use formal legal language in the phishing emails to pressure recipients into compliance, increasing the likelihood of infection. The campaign is notable for its fileless approach, as the malware is loaded directly into memory rather than being written to disk. This method complicates detection and remediation efforts for security teams. The infection chain leverages social engineering, technical obfuscation, and multiple stages to maximize its effectiveness. Researchers have also observed creative obfuscation within the SVG files, such as disguising malicious code with food and recipe-related variable names. The campaign demonstrates a high level of technical sophistication and adaptability, exploiting both human and technical vulnerabilities. Organizations are advised to educate users about the risks of opening unexpected attachments, especially SVG files, and to implement robust endpoint protection capable of detecting fileless threats. The campaign underscores the ongoing evolution of phishing tactics and the need for continuous vigilance in email security. Security teams should review their email filtering and endpoint monitoring policies to address this emerging threat vector. The use of password-protected archives and legitimate-seeming legal notices increases the campaign's success rate, making it a significant concern for enterprises.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Follow-on reporting highlighted related SVG phishing activity involving PureRAT and noted targeting in Ukraine and Vietnam. This expanded the public technical picture of the broader SVG-based phishing threat cluster.
Security researchers disclosed that the SVG-based campaign was delivering Amatera Stealer and PureMiner malware to victims in Ukraine. Multiple reports published over the following days described the same operation and its malware payloads.
A phishing campaign began targeting people in Ukraine with emails impersonating Ukrainian police and carrying malicious SVG attachments. The lures used spoofed law-enforcement notices to trick recipients into opening fileless phishing content.
9 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcedarkreading.com
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourcebankinfosecurity.com
Open sourcehackread.com
Open sourcefeeds.fortinet.com
Open sourcegovinfosecurity.com
Open sourcemalwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.