Security verification prompt | Image: Microsoft Threat Intelligence
Microsoft Threat Intelligence has revealed details of a credential phishing campaign that likely harnessed AI-generated code to enhance its obfuscation techniques and slip past traditional defenses. While the campaign was ultimately blocked, it illustrates how cybercriminals are beginning to integrate large language models (LLMs) into their toolkits, raising the stakes for defenders worldwide.
According to Microsoftβs analysis, βthe activity obfuscated its behavior within an SVG file, leveraging business terminology and a synthetic structure to disguise its malicious intent.β The code was so complex that Microsoftβs own Security Copilot concluded it was βnot something a human would typically write from scratch due to its complexity, verbosity, and lack of practical utility.β
The attackers crafted SVG attachments disguised as PDFs, embedding malicious scripts behind what looked like a business performance dashboard filled with invisible chart elements. Business-related terms such as βrevenue,β βoperations,β and βriskβ were concatenated into hidden attributes, later decoded into executable payloads.
The campaign, detected on August 18, leveraged a compromised small business email account to distribute its lures. Messages were self-addressed β the sender and recipient were the same β while the real victims were hidden in the BCC field, a tactic designed to βbypass basic detection heuristics.β
The attachment, named β23mb β PDF-6 pages.svg,β was designed to appear like a standard PDF file, tricking users into opening it. Once launched, the SVG redirected victims to a fake CAPTCHA page intended to build trust before leading to a credential-harvesting portal.
Microsoft Security Copilot identified several indicators suggesting the obfuscation was machine-generated:
- βOverly descriptive and redundant namingβ (e.g., processBusinessMetricsf43e08)
- βModular and over-engineered code structureβ resembling textbook AI output
- βVerbose, generic commentsβ written in formal business language
- βFormulaic obfuscation techniquesβ like staged data transformation
- βUnusual use of CDATA and XML declarationβ β technically correct but unnecessary
These traits, Microsoft noted, are consistent with AI/LLM-generated code.
Despite the sophistication, Microsoft Defender for Office 365βs AI-powered protections successfully stopped the attack. As the report stresses, βAI-enhanced threats, while evolving, are not undetectableβ¦ an attackerβs use of AI often introduces new artifacts that can be leveraged for detection.β
Detection was aided by multiple factors: suspicious file naming, unusual use of SVG as a payload, redirect patterns, and session tracking behaviors on the phishing site. These infrastructural and behavioral signals remained visible despite the attackerβs obfuscation attempts.
While this campaign was limited and primarily targeted US-based organizations, it signals a growing trend. βLike many transformative technologies, AI is being adopted by both defenders and cybercriminals,β Microsoft warns.
Related Posts:
- SVG Phishing Surge: How Image Files Are Being Weaponized to Steal Credentials
- SVG Files Weaponized: Phishing Attacks Embed HTML Code
- Sophos Uncovers Rising Threat of SVG-Based Phishing Attacks
- SVG Files: The Emerging Vector of Cyber Threats
- SVG Attacks: How GULoader Malware Sneaks into Your Network
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.