Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Passages

(3,678 posts)
Mon Sep 29, 2025, 09:39 AM Sep 29

Microsoft Flags AI-Driven Phishing: LLM-Crafted SVG Files Outsmart Email Security

Sep 29, 2025
Ravie Lakshmanan

Microsoft is calling attention to a new phishing campaign primarily aimed at U.S.-based organizations that has likely utilized code generated using large language models (LLMs) to obfuscate payloads and evade security defenses.

"Appearing to be aided by a large language model (LLM), the activity obfuscated its behavior within an SVG file, leveraging business terminology and a synthetic structure to disguise its malicious intent," the Microsoft Threat Intelligence team said in an analysis published last week.

The activity, detected on August 28, 2025, shows how threat actors are increasingly adopting artificial intelligence (AI) tools into their workflows, often with the goal of crafting more convincing phishing lures, automating malware obfuscation, and generating code that mimics legitimate content.

In the attack chain documented by the Windows maker, bad actors have been observed leveraging an already compromised business email account to send phishing messages to steal victims' credentials. The messages feature lure masquerading as a file-sharing notification to entice them into opening what ostensibly appears to be a PDF document, but, in reality, is a Scalable Vector Graphics (SVG) file.
https://thehackernews.com/2025/09/microsoft-flags-ai-driven-phishing-llm.html?_m=3n%2e009a%2e3785%2eqb0ao44uux%2e2tma

Be careful out there.

3 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Microsoft Flags AI-Driven Phishing: LLM-Crafted SVG Files Outsmart Email Security (Original Post) Passages Sep 29 OP
Good to know. Thanks for posting. lastlib Sep 29 #1
Many, many years ago canetoad Sep 29 #2
We have to be guarded, no doubt about it. Passages Sep 29 #3

lastlib

(26,828 posts)
1. Good to know. Thanks for posting.
Mon Sep 29, 2025, 11:05 AM
Sep 29

Be careful opening (or clicking on) unknown pdf files, folks!

canetoad

(19,603 posts)
2. Many, many years ago
Mon Sep 29, 2025, 05:00 PM
Sep 29

There was an email hack/scam that involved a 1px by 1px transparent image file. So long ago that I can't remember the full details. Our mania for sharing images is going to get us in the end. SVG stands for Scalable Vector Graphic - such as Adobe Illustrator.

Thanks for posting this, it always pays to look out for stuff like this.

Latest Discussions»Help & Search»Computer Help and Support»Microsoft Flags AI-Driven...