AI-Themed Lures: Cyberattackers' New Bait
Cyberattackers are leveraging AI-themed lures to trick users into divulging sensitive information, and Microsoft Defender is fighting back.
A recent wave of campaigns impersonate popular AI platforms and tools, including ChatGPT, Microsoft Copilot, DeepSeek, and Claude. These attacks use phishing, search-driven malware campaigns, and malvertising to make it difficult for users to distinguish between legitimate and malicious communications.
The goal is not to compromise the AI services themselves but to exploit user trust in these platforms. The attacks often rely on multi-stage redirection chains and disposable infrastructure, making them challenging to detect and disrupt.
Microsoft Defender's anti-phishing policies can help detect spoofing and impersonation attempts, including user and domain impersonation. Safe Links provides URL scanning and detonation during mail flow, while Safe Attachments analyzes attachments in a virtual environment before delivery.
When AI-powered attacks move beyond the inbox, Defender helps connect the evidence by correlating signals from email and collaboration tools, endpoints, identities, and software as a service (SaaS) apps. This enables security teams to see whether the same lure led to a clicked link, a downloaded payload, or endpoint activity.
Defender's powerful response capability, attack disruption, contains compromised assets during attacks to prevent further lateral movement while security teams investigate and remediate. Recent statistics show that Defender disrupted over 45,000 AiTM attacks each month.