BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Microsoft Warns of AI-Driven Phishing Using Obfuscated SVG Files

Microsoft uncovers AI-powered phishing campaign using obfuscated SVG files to steal U.S. business credentials

  • Microsoft identified an AI-assisted phishing campaign targeting U.S. organizations using obfuscated SVG files.
  • The scam uses compromised business emails to send messages disguised as file-sharing notifications with malicious SVG attachments.
  • The SVG files contain hidden code employing business-related language and structure, likely generated by large language models (LLMs), to evade detection.
  • The phishing leads victims to complete CAPTCHAs before reaching fake login pages to steal credentials.
  • Other recent phishing campaigns use .XLAM attachments and information stealers, showing evolving attack methods.

Microsoft has reported a new phishing campaign detected on August 28, 2025, that uses Artificial Intelligence to create obfuscated payloads. The campaign mainly targets organizations in the United States by sending phishing emails designed to bypass security defenses through code likely generated by large language models (LLMs). The emails aim to steal credentials by embedding malicious content in SVG files disguised as PDF documents.

- Advertisement -

According to the Microsoft Threat Intelligence team, these phishing messages come from compromised business email accounts and use a technique where the sender and receiver addresses match, while actual targets are hidden in the BCC field to avoid detection. The SVG files sent are text-based and support embedded scripting, which enables attackers to hide malicious code inside seemingly legitimate visuals.

The file structure resembles a business analytics dashboard, making it look harmless to casual inspection. The malicious payload is further disguised through a sequence of business-related terms such as “revenue,” “operations,” and “growth,” a tactic suggesting it was created using an AI language model. “The program was not something a human would typically write from scratch due to its complexity, verbosity, and lack of practical utility,” said Microsoft’s analysis using Security Copilot. The file redirects users to a CAPTCHA page before leading to fake login pages designed to capture user credentials.

Microsoft highlighted SVG files are attractive to attackers because they allow JavaScript and dynamic content to be embedded directly, making it difficult for security tools to detect threats. Features like invisible SVG elements and encoded attributes further help in avoiding static analysis and sandboxing.

Separately, Forcepoint disclosed another multi-stage phishing campaign involving .XLAM email attachments that execute shellcode to deliver the XWorm Remote Access Trojan (RAT). This attack uses obfuscated secondary payloads and reflective DLL injections to maintain persistence and exfiltrate data.

- Advertisement -

Recent weeks have also seen phishing campaigns using lures related to the U.S. Social Security Administration and copyright infringement. These often distribute information stealers like Lone None Stealer and PureLogs Stealer. Cofense reported that one such campaign spoofs legal firms and uses a Telegram bot profile to hide its payloads, showing rising sophistication in phishing tactics.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Critical Flaws Found in vm2 Node.js Sandbox Library

vm2 Node.js library users must urgently update to version 3.11.2 to patch twelve critical...

US Bitcoin Reserve & Crypto Law Clarity Weeks Away

White House advisor Patrick Witt says the CLARITY Act could pass by July 4,...

Musk Claims He’ll End Up Paying Trillions In Taxes

Elon Musk claims a combined 45% federal and state tax rate applies when he...

First Blockchain-Bank US Treasury Trade Settled

Financial giants JPMorgan and Mastercard executed the first cross-border, cross-bank redemption of a tokenized...

Chrome Silently Downloads 4GB Gemini AI Model Without User Consent

Google Chrome is downloading a 4GB AI model file called weights.bin to user devices...

Must Read

5 Best Crypto Jobs Sites To Land Your Next Six Figure Job

The cryptocurrency and blockchain job market has exploded. With new blockchain start-ups and projects being founded at a blistering pace, the demand for workers...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading