> ## Content Index
> Fetch the complete content index at: https://f4n6.co.uk/llms.txt
> Use this file to discover other available public pages before exploring further.

# Detect and disrupt AI-themed attacks with Microsoft Defender
- URL: https://f4n6.co.uk/security-feed/detect-and-disrupt-ai-themed-attacks-with-microsoft-defender/
- Published: 2026-09-11T12:02:03.000Z
- Updated: 2026-09-11T12:02:03.000Z
- Author: Jeff Davies
- Tags: #security-feed, Storm-3075

## 1\. Executive summary

Microsoft Threat Intelligence reports a sustained wave of campaigns impersonating major AI brands — ChatGPT, Microsoft Copilot, DeepSeek and Claude — as lures for phishing, malvertising and SEO-poisoned malware delivery. Confirmed activity includes a ChatGPT-themed phishing kit that sent up to 100,000 emails in a single day to targets in Switzerland, Austria and South Africa to harvest payment-card and personal data, malvertising for a fake AI Windows plugin delivering the Vidar stealer, a Claude-themed AiTM credential-and-token harvesting campaign, and fraudulent DeepSeek installers distributed via GitHub. The initial access broker tracked as Storm-3075 has used AI-themed malvertising to distribute payloads for multiple downstream actors — attribution to Storm-3075 is unconfirmed (no MITRE ATT&CK profile exists for this actor; the designation rests solely on Microsoft's reporting). No CVEs are in scope and no CISA-KEV exploitation state applies to this item. For EMEA financial services the bottom-line risk is credential theft, payment-card fraud and infostealer infections entering through staff curiosity about AI tools, with downstream potential for account takeover and fraud execution.

## 2\. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. The activity described is a broad, ongoing criminal campaign pattern rather than an incident at a specific financial entity, and no fact in this item triggers a distinctive obligation under the articles in scope (DORA Art. 17, 18, 19, 24, 28, 29, 30; NIS2 Art. 21(2)(d), 23; UK NIS 2018). Clients that suffer a confirmed compromise arising from these lures should reassess against DORA Art. 18 (classification of ICT-related incidents and cyber threats) and, if classified major, DORA Art. 19 (reporting of major ICT-related incidents to competent authorities) at that point.

## 3\. Technical analysis & attack chain

This is a campaign-trend item covering multiple distinct operations sharing an AI-brand lure theme. The confirmed attack chains, per Microsoft and corroborating sources:

### Chain A — ChatGPT-themed payment-card phishing (corroborated: Microsoft Threat Intelligence, June and September 2026 blogs).

1. Bulk email delivery using the sender display name "ChatGPT" and subject line "To ensure your ChatGPT Plus continues to work – please update your payment method", with a ChatGPT logo in the email body.
2. The lure creates urgency: recipients are told their ChatGPT Plus subscription will be downgraded to a free plan unless a new payment method is provided within seven days.
3. The email's "Update payment method" button does not link directly to attacker infrastructure. It routes through a multi-stage redirect chain that abuses legitimate services to borrow domain reputation and defeat URL reputation checks: first hop grupoconstat\[.\]bitrix24\[.\]com\[.\]br (a legitimate CRM service), then awstrack\[.\]me (an Amazon click-tracking domain), before final redirection to the attacker-controlled phishing page (the June source is truncated mid-chain; the terminal phishing domain is not published in the material provided).
4. The phishing page collects credit-card numbers and personal data (names, addresses).
5. Scale and targeting: 4,500 emails on May 5, 2026, 97% to South Africa; peak volume of 100,000 emails in a single day to Switzerland, Austria and South Africa, hitting higher education and professional services among other industries.

### Chain B — AI-themed malvertising and stealer delivery (single-sourced: Microsoft).

1. Malvertising (malicious online ads) themed around AI tools, including a fake "AI Windows plugin".
2. Users are driven through redirect chains to a malicious download.
3. Payload observed: the Vidar stealer. Separately, the June Microsoft report attributes AI-themed malvertising payload distribution to the initial access broker Storm-3075, delivering malware signed via a malware-signing-as-a-service (MSaaS) offering attributed to the financially motivated actor Fox Tempest, on behalf of multiple downstream actors. Both the Storm-3075 and Fox Tempest attributions are Microsoft-only and unconfirmed against MITRE ATT&CK; treat as single-sourced and verify before enforcement action.
4. A further variant distributes fraudulent DeepSeek installers through GitHub.

**Chain C — Claude-themed AiTM (single-sourced: Microsoft).** A Claude-themed campaign harvested credentials and access tokens via adversary-in-the-middle phishing — the actor proxies the real sign-in page, capturing both credentials and session tokens to bypass MFA. No further technical detail is published in the provided material.

**Chain D — device-code fraud lure disrupted by Defender (single case study, Microsoft).** An attacker used a document-sharing lure to trick a user into initiating a legitimate Microsoft device code sign-in flow, avoiding traditional credential theft. Defender correlated the device-code authentication with follow-on identity and email telemetry and contained the attack within four minutes, before persistence, inbox-rule creation or payroll fraud. This illustrates the endpoint of these lures: identity compromise pivoting to financial fraud.

**Corroborating context.** Sophos X-Ops independently reviewed 12 months of MDR casework (July 2, 2025 – June 29, 2026): of 86 cases initially tagged for AI involvement, 34 were confirmed malicious activity involving AI, with attackers impersonating AI brands (Perplexity, Claude, ChatGPT, Copilot) to deliver information stealers, backdoors and malicious browser extensions. Microsoft has also observed AI chatbot interactions surfacing malicious download links (LLM search-result poisoning) in a cryptojacking campaign impersonating system utilities — an adjacent delivery vector clients should be aware of.

**Key point for defenders:** none of these campaigns represent a compromise of the AI vendors referenced. The AI branding is purely a social-engineering wrapper over established techniques — urgency, impersonation, multi-stage redirects, disposable infrastructure. A single lure can traverse email → link → download → identity/endpoint compromise, and must be correlated across surfaces, not triaged as isolated events.

## 4\. Mitigation & containment

### P1 — within 24 hours

- Enable/tune anti-phishing policies in Microsoft Defender (or equivalent email gateway): user impersonation, domain impersonation, first-contact sender safety tips, and mailbox intelligence. These directly counter the "ChatGPT" display-name spoofing observed in Chain A.
- Ensure Safe Links (URL scanning and detonation at mail flow, plus time-of-click verification across email, Teams and Microsoft 365 apps) is enforced for all users — critical against the delayed-activation and redirect-chain tactics described.
- Ensure Safe Attachments detonation is configured, and confirm post-delivery (ZAP) filtering is on to purge malicious messages already delivered.
- Block the observed redirect-chain indicators at email/web gateways where they are not legitimately required: grupoconstat\[.\]bitrix24\[.\]com\[.\]br and awstrack\[.\]me as phishing redirect hops (note: both are legitimate services — block as redirect sources in phishing context, not as outright malicious infrastructure).
- Hunt your environment: search mail logs for the exact subject string "To ensure your ChatGPT Plus continues to work – please update your payment method" and sender display name "ChatGPT"; review any clicks and reset credentials/cancel cards for affected users.

### P2 — within 72 hours

- Enable Defender attack disruption (automatic containment of compromised accounts/assets) if licensed — Microsoft reports it contains 81,000+ compromised accounts and disrupts 45,000+ AiTM attacks monthly, and contained the Chain D device-code attack in four minutes.
- Review and restrict device code flow (disable the device code authentication method for users who do not require it) — it was abused in the observed fraud case to bypass credential-theft detection.
- Brief accounts payable and finance teams: AI-themed lures pair with executive-impersonation invoice fraud (Microsoft separately observed a 1M+ email campaign pushing \~$50,000 ACH payments via fabricated ServiceNow invoices). Reinforce out-of-band payment verification and callback procedures.
- User awareness messaging: no AI vendor will request payment-method updates via emailed links; treat "AI plugin", "new model release" and "policy update" lures as high-suspicion categories.

### P3 — within 7 days

- Correlate email, identity, endpoint and SaaS signals into a single incident view (Defender attack-story correlation or equivalent SOC process) so multi-surface lures are investigated as one event.
- Audit egress/DNS for contact with newly registered lookalike domains containing your organisation's name as a subdomain (a technique Microsoft reports in adjacent identity-compromise campaigns).
- Review third-party CRM and click-tracking domains in mail-flow policy: the Chain A abuse of bitrix24 and awstrack shows reputation laundering through legitimate SaaS is active; consider link-isolation/browser sandboxing for clicked URLs.

## 5\. Indicators of compromise

| Type                | Value                                                                               | Confidence                                              | Source                                    |
| ------------------- | ----------------------------------------------------------------------------------- | ------------------------------------------------------- | ----------------------------------------- |
| domain              | grupoconstat\[.\]bitrix24\[.\]com\[.\]br                                            | High (observed redirect hop; legitimate service abused) | Microsoft Threat Intelligence, 2026-06-08 |
| domain              | awstrack\[.\]me                                                                     | High (observed redirect hop; legitimate service abused) | Microsoft Threat Intelligence, 2026-06-08 |
| email-subject       | "To ensure your ChatGPT Plus continues to work – please update your payment method" | High                                                    | Microsoft Threat Intelligence, 2026-06-08 |
| sender-display-name | ChatGPT                                                                             | High                                                    | Microsoft Threat Intelligence, 2026-06-08 |

Note: the terminal phishing domains of the redirect chain, the Vidar sample hashes, the GitHub repositories hosting fake DeepSeek installers, and the Claude AiTM infrastructure are not published in the provided material and are therefore not listed. The two domains above are legitimate services abused as redirect hops — do not treat them as attacker-owned infrastructure.

```iocs
domain  grupoconstat[.]bitrix24[.]com[.]br
domain  awstrack[.]me
email-subject  To ensure your ChatGPT Plus continues to work – please update your payment method
sender-display-name  ChatGPT

```

### Behavioural indicators

| Behaviour                                                                                                                                    | Where to observe                                                         | Confidence                         |
| -------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------ | ---------------------------------- |
| Multi-stage redirect chains through legitimate CRM/click-tracking domains before reaching credential or card-collection pages                | Email gateway URL detonation, proxy/web logs, Safe Links click telemetry | High                               |
| Device code authentication flow initiated following a document-sharing lure, followed by suspicious sign-in and inbox-rule creation attempts | Entra ID sign-in logs (device code auth events), Defender attack story   | High (single published case study) |
| AI-brand display-name spoofing with payment-urgency messaging (subscription downgrade within 7 days)                                         | Mail flow / anti-phishing policy logs                                    | High                               |
| Malvertising redirect chains delivering Vidar stealer via fake "AI plugin" downloads                                                         | Endpoint EDR, web proxy logs                                             | Medium (single-sourced)            |

## 6\. Detection

```yara
rule AI_Themed_Phishing_Lure_Subject
{
    meta:
        author = "Adverse Trace"
        date = "2026-09-10"
        reference = "https://www.microsoft.com/en-us/security/blog/2026/06/08/ai-brands-as-bait-how-threat-actors-are-using-the-ai-hype-in-social-engineering/"
        description = "Matches the exact ChatGPT-themed phishing subject line and display name observed in the May 2026 payment-card harvesting campaign. Intended for scanning extracted email bodies/headers or mail-archive artefacts."
    strings:
        $subject = "To ensure your ChatGPT Plus continues to work" fullword ascii
        $subject2 = "please update your payment method" fullword ascii
        $downgrade = "downgraded to a free plan" ascii
        $btn = "Update payment method" ascii
    condition:
        all of them
}

```

Note: the strings above are the exact lure text artefacts published by Microsoft. No file hashes, mutexes, registry keys or payload strings (e.g. for the Vidar sample) are present in the source material, so no payload-based rule can be authored without fabrication. For the Vidar delivery chain, rely on EDR behavioural detection of stealer activity and Safe Attachments detonation rather than signature matching.

A Sigma rule is not emitted: the source material provides no specific process, registry or scheduled-task artefacts. The strongest available log-based detection is an exact-match alert on the subject line and display name above in your mail telemetry, plus alerting on device-code authentication events (SignInLogs, `authenticationProtocol: deviceCode`) that are not user-initiated.

## 7\. Sources

- Microsoft Security Blog — *Detect and disrupt AI-themed attacks with Microsoft Defender* — https://www.microsoft.com/en-us/security/blog/2026/09/10/detect-and-disrupt-ai-themed-attacks-with-microsoft-defender/ — 2026-09-10
- Microsoft Threat Intelligence — *AI brands as bait: How threat actors are using the AI hype in social engineering* — https://www.microsoft.com/en-us/security/blog/2026/06/08/ai-brands-as-bait-how-threat-actors-are-using-the-ai-hype-in-social-engineering/ — 2026-06-08
- Microsoft Threat Intelligence — *Protecting organizations from AI-assisted executive impersonation and invoice fraud* — https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/ — 2026-09-10
- Microsoft Threat Intelligence — *Passkey-themed social engineering leads to identity and cloud compromise* — https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/ — 2026-09-09
- Microsoft Threat Intelligence — *From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities* — https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/ — 2026-05-26
- Help Net Security — *Attackers impersonate popular AI brands to spread malware* (reporting Sophos X-Ops MDR review) — https://www.helpnetsecurity.com/2026/08/21/ai-brand-impersonation-malware-malware-research/ — 2026-08-21
- Sophos — *Fake AI, real malware: Attackers impersonating AI brands* — https://www.sophos.com/en-gb/blog/fake-ai-real-malware-attackers-impersonating-ai-brands — 2026 (accessed 2026-09-10)

## 8\. Adverse Trace position

This is a social-engineering trend, not a new vulnerability class — severity for EMEA financial services is **medium**: no exploited CVE, no KEV entries, no compromise of the referenced AI vendors, but high-volume, well-executed lures with direct financial impact paths (card harvesting, Vidar infostealer infections, AiTM token theft, ACH invoice fraud). The Storm-3075 and Fox Tempest attributions and the Vidar/GitHub delivery details are single-sourced to Microsoft — we treat them as credible but unconfirmed, and clients should not take enforcement or blocking action against named infrastructure beyond the published redirect-chain domains without independent verification. The durable defensive play is not brand-specific blocking but cross-surface correlation: email, identity, endpoint and SaaS signals triaged as one incident, device-code flow restricted, payment verification procedures hardened, and time-of-click URL verification enforced. Adverse Trace will monitor for publication of the terminal phishing infrastructure, Vidar sample hashes and the fake DeepSeek GitHub repositories, and will issue a follow-up note if corroborating indicators emerge.

---

[Read the original source →](https://www.microsoft.com/en-us/security/blog/2026/09/10/detect-and-disrupt-ai-themed-attacks-with-microsoft-defender/?ref=f4n6.co.uk)

*Published via PulseTrace — Adverse Trace threat intelligence.*