Advancements in Artificial Intelligence have revolutionized many industries and made our work easier, but have also given rise to new types of cyberattacks. According to recent Microsoft research, AI-themed attacks are on the rise. These new cyberattacks let cybercriminals use artificial intelligence to hack users’ computers or steal confidential information. This article covers important highlights of AI-themed attacks.

AI-themed attacks on the rise, says Microsoft
AI-themed attacks differ significantly from traditional cyberattacks like phishing, but the objective is the same. While both methods aim to trick users into stealing confidential information, AI-powered attacks are more advanced and have a higher success rate. The reason for a high success rate is the advanced attack pattern. Now, hackers are using the names of popular AI brands like ChatGPT, Claude, and DeepSeek to create fake campaigns, malicious Windows plugins, and malicious Windows installers to trick users and steal their confidential information.

The Microsoft research team has recently observed several AI brand campaigns, including:
- A ChatGPT-themed phishing kit built to harvest credit card data.
- A Claude-themed campaign that harvested credentials and access tokens through adversary-in-the-middle (AiTM) techniques.
- Malvertising for a fake AI Windows plugin that delivered the Vidar stealer.
- Fraudulent DeepSeek installers distributed through GitHub.
Microsoft Defender helps stop AI-themed attacks
Microsoft Defender disrupts AI-themed attacks by stopping them before they reach users’ inboxes. It uses advanced anti-phishing policies to detect fake updates and notices. If the attack relies on URLs, Defender’s Safe Links scans and detonates URLs during mail flow, plus verifies them at click time when a user selects a link in email, Microsoft Teams, or supported Microsoft 365 apps. For cyberattack campaigns that use fake installers, malicious downloads, or weaponized attachments, Safe Attachments adds another layer by detonating attachments in a virtual environment before delivery when policies are configured.

AI-powered attacks do not stop at email; they aim to gain the highest level of access possible and move across identities, devices, and data through the compromised email accounts. When a cyberattack moves beyond the inbox, Defender helps connect the evidence. It connects signals from emails, endpoints, and SaaS apps to map the full attack story.

For multi-stage, multi-domain attacks like business email compromise or AiTM, Defender’s powerful, built-in response capability, Attack Disruption, helps prevent further lateral movement while security teams investigate and remediate. Attack Disruption automatically contains compromised email accounts. Currently, it has more than 81,000 compromised user accounts monthly and is disrupting more than 45,000 AiTM attacks each month. The above image shows how Microsoft Defender disrupted a business email compromise within 4 minutes in a recent case study. However, the response time may vary by scenario.
AI-themed lures are \new types of cyberattacks, and they keep evolving. The aim of these attacks will remain the same. Therefore, organizations have to adopt new ways and technologies to build advanced protection models that disrupt the entire attack chain, says Microsoft.