Recent research from Microsoft Threat Intelligence reveals a surge in cyberattacks leveraging the hype surrounding artificial intelligence (AI). Cybercriminals are increasingly impersonating well-known AI platforms such as ChatGPT, Microsoft Copilot, DeepSeek, and Claude to execute phishing campaigns, malware distribution, and malvertising. One notable campaign involved a ChatGPT-themed phishing scheme that sent out as many as 100,000 emails in a single day, tricking users into providing sensitive payment information and stealing personal data. These attacks do not indicate a breach of the AI services themselves but rather illustrate how attackers exploit the trust associated with these popular brands.
The tactics employed in these campaigns are familiar yet evolving. Cyberattackers are using urgency and curiosity to lower user defenses, presenting messages about new AI features or updates that mimic legitimate communications. This trend is significant as it highlights the potential for AI-themed lures to become a persistent threat, capitalizing on the excitement and urgency that AI generates among users.
The attack pattern is evolving
Microsoft’s research has identified several specific AI-themed campaigns, including:
- A phishing kit themed around ChatGPT designed to collect credit card information.
- A Claude-themed campaign utilizing adversary-in-the-middle (AiTM) techniques to harvest credentials and access tokens.
- Malvertising for a fraudulent AI Windows plugin that delivered the Vidar stealer.
- Distribution of fake DeepSeek installers via GitHub.
These campaigns demonstrate a shift in the cybercriminal landscape, where attackers are quickly commoditizing AI-themed tactics to exploit emerging trends. This evolution underscores the need for organizations to adopt a comprehensive view of cyber threats, recognizing that a single AI-themed lure can initiate a multi-stage attack.
Turning AI lures into dead ends with Microsoft Defender
To combat these threats, Microsoft Defender offers robust anti-phishing policies that can detect impersonation attempts and suspicious sender characteristics. Features like Safe Links and Safe Attachments provide additional layers of protection by scanning URLs and attachments for malicious content before they reach users. This proactive approach is crucial in an environment where cyberattackers frequently use deceptive tactics to bypass security measures.
Protect against multi-stage attacks with attack disruption
AI-powered attacks extend beyond email, aiming to gain extensive access across networks. Microsoft Defender correlates signals from various sources to create a comprehensive attack narrative, allowing security teams to identify and disrupt threats effectively. The Defender platform has successfully contained over 81,000 compromised user accounts and disrupted more than 45,000 adversary-in-the-middle attacks each month, showcasing its effectiveness in real-time threat response.
As cybercriminals continue to exploit the momentum surrounding AI, organizations must remain vigilant. The evolving nature of these threats necessitates a proactive and integrated security strategy that connects prevention, detection, investigation, and response across the attack landscape.
For further details, refer to the full report by Microsoft Threat Intelligence.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.



