Skip to content
Auto-CTI
Back to all deep dives
MICROSOFT SECURITY BLOG

Detect and disrupt AI-themed attacks with Microsoft Defender

HIGH AI-themed phishing credential harvesting ChatGPT impersonation Teams-based attacks

Strategic summary

Microsoft Threat Intelligence has observed a growing set of campaigns impersonating popular AI platforms such as ChatGPT, Microsoft Copilot, DeepSeek, and Claude. Attackers use phishing, search-driven malware, and malvertising to steal credentials, credit card data, and access tokens. For organizations like Joel Traber AG, a manufacturing company in the DACH region, these AI-themed lures must be viewed as multi-stage attack chains rather than isolated events. Microsoft Defender provides integrated protection that can detect and disrupt these attacks early.

Key findings

  • ChatGPT-themed phishing campaigns sent up to 100,000 emails in a single day to trick users into updating payment information and steal personal and credit card data.
  • Threat actors impersonated AI brands including Claude, DeepSeek, and Microsoft Copilot through malvertising, fraudulent installers, and adversary-in-the-middle techniques.
  • An initial access broker tracked as Storm-3075 used AI-themed malvertising to distribute payloads for multiple downstream actors, showing rapid commoditization.
  • These campaigns often follow a multi-stage path from email to malicious link, suspicious download, and finally identity or endpoint compromise.
  • Microsoft Defender helps turn AI lures into dead ends by connecting signals across email, identity, endpoint, and cloud to stop attacks early.

Relevance for you

Cyberattackers are weaponizing AI platform impersonation (ChatGPT, Copilot, Claude, DeepSeek) at scale (up to 100,000 emails per day) for phishing, credential harvesting, and malvertising, with increasing automation and Teams-based social engineering.

Risk score

20
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
15.00
industry weight
1.10
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

ESC