Close Menu
TechUpdateAlert

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    My Health Anxiety Means I Won’t Use Apple’s or Samsung’s Smartwatches. Here’s Why

    December 22, 2025

    You can now buy the OnePlus 15 in the US and score free earbuds if you hurry

    December 22, 2025

    Today’s NYT Connections: Sports Edition Hints, Answers for Dec. 22 #455

    December 22, 2025
    Facebook X (Twitter) Instagram
    Trending
    • My Health Anxiety Means I Won’t Use Apple’s or Samsung’s Smartwatches. Here’s Why
    • You can now buy the OnePlus 15 in the US and score free earbuds if you hurry
    • Today’s NYT Connections: Sports Edition Hints, Answers for Dec. 22 #455
    • Android might finally stop making you tap twice for Wi-Fi
    • Today’s NYT Mini Crossword Answers for Dec. 22
    • Waymo’s robotaxis didn’t know what to do when a city’s traffic lights failed
    • Today’s NYT Wordle Hints, Answer and Help for Dec. 22 #1647
    • You Asked: OLED Sunlight, VHS on 4K TVs, and HDMI Control Issues
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechUpdateAlertTechUpdateAlert
    • Home
    • Gaming
    • Laptops
    • Mobile
    • Software
    • Reviews
    • AI & Tech
    • Gadgets
    • How-To
    TechUpdateAlert
    Home»How-To»Microsoft thwarted phishing campaign after detecting AI-generated code inside malicious attachments
    How-To

    Microsoft thwarted phishing campaign after detecting AI-generated code inside malicious attachments

    techupdateadminBy techupdateadminOctober 1, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
    Share
    Facebook Twitter LinkedIn Pinterest Email


    • AI generated code used in phishing campaign, blocked by Microsoft Defender
    • Attackers used SVG file disguised as PDF, with hidden business themed code inside
    • Security Copilot flagged AI style traits, like verbose identifiers and generic comments

    AI code is now used across industries for a range of tasks, and in cybersecurity, both security teams and attackers are increasingly turning to large language models to support their work.

    Defenders apply AI to detect and respond to threats at scale, while attackers experiment with it to craft phishing lures, generate obfuscated code, and disguise malicious payloads.

    Microsoft Threat Intelligence recently detected and blocked a phishing campaign it believed used AI-generated code to hide its payload inside an SVG file.


    You may like

    Polished but not practical

    The campaign used a compromised small business email account to send self addressed messages with actual targets hidden in BCC fields, and the attachment was named to resemble a PDF while carrying scriptable SVG content.

    The SVG file included hidden elements made to look like a business dashboard, while a script inside it turned business related words into code that revealed a hidden payload.

    When opened, the file redirected users to a CAPTCHA gate, a common social engineering tactic that can lead to a fake sign in page intended to harvest credentials.

    The obfuscation relied on concatenated business words and formulaic code patterns rather than cryptographic techniques.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Security Copilot analyzed the file and flagged markers consistent with LLM output, such as long descriptive identifiers, repetitive modular structures, generic comments, and an unusual combination of XML declaration and CDATA.

    These traits made the code look polished on the surface but not practical, which led analysts to believe it was probably generated by AI.

    The researchers used AI powered tools in Microsoft Defender for Office 365 to piece together clues that were harder for attackers to hide.

    The system flagged the unusual self-addressed email pattern, the odd SVG file disguised as a PDF, the redirect to a known phishing site, the hidden code inside the file, and the tracking methods used on the phishing page.

    The incident was limited, easily blocked, and primarily targeted US organizations, but Microsoft notes that it illustrates how attackers are increasingly experimenting with AI to craft convincing lures and complex payloads.

    Via Infosecurity Magazine

    You might also like

    AIgenerated attachments Campaign Code detecting Malicious Microsoft phishing thwarted
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWindows 11 version 25H2 is out, but when will you get it?
    Next Article CoD: Black Ops 7’s wallhack killstreak is receiving a frenzy of criticism, but isn’t the point of killstreaks that they’re unfair?
    techupdateadmin
    • Website

    Related Posts

    Mobile

    Launching my first NotebookLM AI-generated podcast taught me one thing you must avoid

    December 20, 2025
    Gadgets

    Microsoft makes theming your Windows 11 PC as easy as phones, but not as much fun

    December 15, 2025
    Gadgets

    McDonald’s pulls its AI-generated Christmas ad after backlash

    December 10, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    NYT Strands hints and answers for Monday, August 11 (game #526)

    August 11, 202545 Views

    These 2 Cities Are Pushing Back on Data Centers. Here’s What They’re Worried About

    September 13, 202542 Views

    Today’s NYT Connections: Sports Edition Hints, Answers for Sept. 4 #346

    September 4, 202540 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Best Fitbit fitness trackers and watches in 2025

    July 9, 20250 Views

    There are still 200+ Prime Day 2025 deals you can get

    July 9, 20250 Views

    The best earbuds we’ve tested for 2025

    July 9, 20250 Views
    Our Picks

    My Health Anxiety Means I Won’t Use Apple’s or Samsung’s Smartwatches. Here’s Why

    December 22, 2025

    You can now buy the OnePlus 15 in the US and score free earbuds if you hurry

    December 22, 2025

    Today’s NYT Connections: Sports Edition Hints, Answers for Dec. 22 #455

    December 22, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    © 2026 techupdatealert. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.