"SVG files (Scalable Vector Graphics) are attractive to attackers because they are text-based and scriptable, allowing them to embed JavaScript and other dynamic content directly within the file," Microsoft said. "First, the beginning of the SVG code was structured to look like a legitimate business analytics dashboard," Microsoft said. The secondary payload functions as a conduit to load a .DLL file in memory. "The second stage .DLL file from memory uses heavily obfuscated packing and encryption techniques," Forcepoint said. "This second stage .DLL file loaded another .DLL file in memory again using reflective DLL injection which was further responsible for final execution of malware."