Loading cryptocurrency prices...

Microsoft Warns of AI-Driven Phishing Using Obfuscated SVG Files

Microsoft uncovers AI-powered phishing campaign using obfuscated SVG files to steal U.S. business credentials

  • Microsoft identified an AI-assisted phishing campaign targeting U.S. organizations using obfuscated SVG files.
  • The scam uses compromised business emails to send messages disguised as file-sharing notifications with malicious SVG attachments.
  • The SVG files contain hidden code employing business-related language and structure, likely generated by large language models (LLMs), to evade detection.
  • The phishing leads victims to complete CAPTCHAs before reaching fake login pages to steal credentials.
  • Other recent phishing campaigns use .XLAM attachments and information stealers, showing evolving attack methods.

Microsoft has reported a new phishing campaign detected on August 28, 2025, that uses Artificial Intelligence to create obfuscated payloads. The campaign mainly targets organizations in the United States by sending phishing emails designed to bypass security defenses through code likely generated by large language models (LLMs). The emails aim to steal credentials by embedding malicious content in SVG files disguised as PDF documents.

- Advertisement -

According to the Microsoft Threat Intelligence team, these phishing messages come from compromised business email accounts and use a technique where the sender and receiver addresses match, while actual targets are hidden in the BCC field to avoid detection. The SVG files sent are text-based and support embedded scripting, which enables attackers to hide malicious code inside seemingly legitimate visuals.

The file structure resembles a business analytics dashboard, making it look harmless to casual inspection. The malicious payload is further disguised through a sequence of business-related terms such as “revenue,” “operations,” and “growth,” a tactic suggesting it was created using an AI language model. “The program was not something a human would typically write from scratch due to its complexity, verbosity, and lack of practical utility,” said Microsoft’s analysis using Security Copilot. The file redirects users to a CAPTCHA page before leading to fake login pages designed to capture user credentials.

Microsoft highlighted SVG files are attractive to attackers because they allow JavaScript and dynamic content to be embedded directly, making it difficult for security tools to detect threats. Features like invisible SVG elements and encoded attributes further help in avoiding static analysis and sandboxing.

Separately, Forcepoint disclosed another multi-stage phishing campaign involving .XLAM email attachments that execute shellcode to deliver the XWorm Remote Access Trojan (RAT). This attack uses obfuscated secondary payloads and reflective DLL injections to maintain persistence and exfiltrate data.

- Advertisement -

Recent weeks have also seen phishing campaigns using lures related to the U.S. Social Security Administration and copyright infringement. These often distribute information stealers like Lone None Stealer and PureLogs Stealer. Cofense reported that one such campaign spoofs legal firms and uses a Telegram bot profile to hide its payloads, showing rising sophistication in phishing tactics.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Lava’s 7% BTC Loan Claim Challenged Over 35% Actual APR

Lava claims to have saved users millions in interest by refinancing Bitcoin-backed loans at...

Bitcoin miners’ stocks plunge amid crypto market downturn

Cryptocurrency miners and related stocks fell sharply due to ongoing macroeconomic challenges.The top 10...

Prosecutors Urge Judge to Uphold Tornado Cash Developer’s Conviction

Prosecutors urge the court to uphold the conviction of Roman Storm, co-founder of Tornado...

Block’s Cash App to Support USDC on Solana for Seamless Payments

Block's Cash App will support payments in USD Coin (USDC) on the Solana blockchain...

Bitcoin Drops Below $100K Amid Data Blackout Fears

Bitcoin Price dropped sharply below $100,000, reaching its lowest since May.October U.S. economic data...
- Advertisement -

Must Read

9 Best Trading Platforms for Crypto Beginners

Many newcomers to the crypto space are looking for platforms to buy, sell and exchange cryptocurrencies. While there are hundreds of crypto exchanges around...