Microsoft Threat Intelligence identified a sophisticated phishing campaign targeting U.S.-based organizations, leveraging artificial intelligence to craft highly convincing and evasive attacks. The campaign was detected in late August 2025 and involved the use of compromised small business email accounts to distribute phishing emails. These emails masqueraded as legitimate file-sharing notifications, enticing recipients to open an attachment that appeared to be a PDF but was actually a Scalable Vector Graphics (SVG) file. The attackers exploited the SVG format's flexibility, embedding dynamic and interactive code that could bypass many traditional security tools. Instead of using standard obfuscation techniques, the malicious payload was hidden within the SVG file by encoding it with a sequence of business-related terms, such as 'revenue,' 'operations,' and 'risk,' making the file appear as standard business data. This approach allowed the attackers to disguise the true intent of the file, which was to redirect users to a fake sign-in page designed to harvest credentials. Microsoft noted that the code within the SVG was likely generated or enhanced using large language models (LLMs), a form of AI that can produce complex, human-like text and code, further complicating detection efforts. The phishing emails also employed a self-addressed tactic, where the sender and recipient addresses matched, with actual targets hidden in the BCC field to evade basic detection heuristics. SVG files are particularly attractive to attackers because they are text-based, scriptable, and support features like invisible elements, encoded attributes, and delayed script execution, all of which can be used to sidestep static analysis and security scanning. Microsoft responded by using its own AI-powered security tools to analyze and block the campaign, highlighting the growing trend of AI versus AI in cybersecurity defense and offense. The campaign underscores the increasing adoption of AI by threat actors to automate the creation of convincing phishing lures and obfuscated malware. The use of compromised business email accounts added legitimacy to the phishing attempts, increasing the likelihood of successful credential theft. The incident demonstrates the evolving threat landscape, where attackers continuously adapt their methods to outpace security defenses. Organizations are advised to enhance their email security protocols, educate users about the risks of unexpected file attachments, and deploy advanced detection tools capable of analyzing complex file formats like SVG. The campaign serves as a warning that traditional security measures may be insufficient against AI-driven threats, necessitating a proactive and adaptive security posture. Microsoft’s public disclosure of the attack provides valuable intelligence for defenders to recognize and mitigate similar threats in the future. The incident also highlights the importance of monitoring for unusual email behaviors, such as self-addressed messages and unexpected file types. As AI becomes more accessible to both attackers and defenders, the arms race in cybersecurity is expected to intensify, with increasingly sophisticated attacks targeting organizations of all sizes.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehackread.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.