Cybersecurity

How Are Organizations Addressing Phishing Attacks Disguised Behind the AI Wave?

Microsoft is tracking campaigns impersonating ChatGPT, Microsoft Copilot, DeepSeek, and Claude to steal payment data and credentials and distribute malware. The article calls for correlating email, identity, device, and cloud application signals to detect and disrupt attacks before they become broader breaches.

2026-09-10
5 min read
13 views
فريق تحرير certi.news
How Are Organizations Addressing Phishing Attacks Disguised Behind the AI Wave?

New phishing and malware campaigns are exploiting the trust and curiosity associated with AI tools by impersonating ChatGPT, Microsoft Copilot, DeepSeek, and Claude. According to Microsoft Threat Intelligence research, these campaigns aim to direct users to credential-stealing pages, malicious downloads, or redirect chains that begin with an advertisement or message appearing to be associated with a well-known AI service.

Microsoft says that one phishing campaign impersonating ChatGPT sent up to 100,000 email messages in a single day and attempted to persuade users to update the payment information for their ChatGPT Plus subscription, targeting personal data and credit card information. The company emphasizes that these campaigns do not mean the impersonated AI services were breached; rather, they represent the use of these brands’ reputations in familiar forms of social engineering.

AI Is a New Cover for Old Tactics

The observed attacks do not necessarily rely on exceptional techniques, but on elements such as urgency, curiosity, and impersonation of a familiar entity. The message may appear as an announcement about the launch of a new model, an update to the policy of a smart assistant, or an add-on claiming to improve the user’s performance. In this sense, the AI topic replaces the traditional lure, such as a fake invoice or shipping notification, while the attacker retains the same objective: lowering the user’s guard and prompting interaction.

The Microsoft team identified multiple campaigns, including a ChatGPT-related phishing package designed to collect card details; a campaign impersonating Claude and using adversary-in-the-middle techniques to steal credentials and access tokens; and malicious advertisements promoting a fake Windows extension and delivering the Vidar information-stealing malware. Fake DeepSeek installers were also distributed through GitHub. In one case, an initial access broker tracked by Microsoft as Storm-3075 used malicious advertisements associated with AI to distribute payloads to multiple criminal entities.

What Changes in Practice for Security Teams?

The core problem does not lie in a single channel. A campaign may begin with an email, then move to a malicious link, a suspicious download, and unusual login behavior, ultimately leading to an account or device compromise. Therefore, analyzing each signal in isolation may prevent security teams from seeing the full attack sequence. Correlating signals from email, collaboration tools, endpoints, identities, and SaaS applications helps determine whether the same lure led to subsequent malicious activity.

Microsoft indicates that anti-phishing policies in Microsoft Defender can examine attempts to impersonate users and domains, first-contact messages, mailbox intelligence signals, and suspicious sender properties. Safe Links also provides link scanning and time-of-click inspection as the message passes through the system, in addition to click-time verification in email, Microsoft Teams, and supported Microsoft 365 applications. Click-time verification becomes more important when a campaign uses multistage redirects or links that appear safe at delivery but later change their destination.

For messages containing fake installers or weaponized attachments, Safe Attachments can run the attachment inside a virtual environment before delivery when the appropriate policies are configured. If the threat is detected after the message has arrived, post-delivery filtering capabilities help remove the malicious content and reduce the period during which users are exposed to it.

Preventing the Move from Email to Account Compromise

When a campaign moves beyond the mailbox, protection depends on understanding the relationship between identity, device, and data. According to Microsoft, Defender combines signals into a single attack story, enabling an analyst to connect a link click or payload download with a risky login or activity on an endpoint.

The company says that attack disruption, built into Defender, can contain the compromised asset during an attack to limit lateral movement, particularly in multistage attacks such as business email compromise or adversary-in-the-middle attacks. Microsoft says the feature contains more than 81,000 compromised user accounts each month and disrupts more than 45,000 AiTM attacks monthly.

In a case study presented by the company, Defender disrupted a business email compromise attack within four minutes of the activity beginning. The attacker used a convincing document-sharing message that prompted the user to initiate a legitimate sign-in flow using a device code, rather than stealing the password through the traditional method. After correlating authentication signals and email activity, Defender recognized the suspicious behavior and stopped the attack before persistence or mailbox rules could be established or payroll fraud could be carried out.

Editorial Perspective

The practical value of this material does not lie in the appearance of a new AI brand on the list of lures, but in confirming that security teams need to assess the entire attack chain. The source establishes the existence of campaigns impersonating well-known services and provides examples of phishing, token theft, and malware, but it does not establish that every campaign using AI is more sophisticated than earlier attacks. The disruption figures and response times cited are data provided by Microsoft about Defender, and results may vary depending on the scenario and protection settings. Therefore, the practical question for organizations remains how integrated their tools are and how capable they are of turning scattered signals into a rapid response—not merely adding a rule that blocks a particular brand name.

News source
Microsoft Security Blog
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news