Cybersecurity researchers have lifted the lid on a previously undocumented threat cluster dubbed GhostRedirector that has managed to compromise at least 65 Windows servers primarily located in Brazil, Thailand, and Vietnam.
The attacks, per Slovak cybersecurity company ESET, led to the deployment of a passive C++ backdoor called Rungan and a native Internet Information Services (IIS) module

VirusTotal finds hidden malware phishing campaign in SVG files – BleepingComputer
VirusTotal finds hidden malware phishing campaign in SVG files BleepingComputer