Hackers Use AI-Generated Code to Obfuscate Malware in Phishing Attacks

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Hackers leveraged AI-generated code to obfuscate malware payloads in phishing campaigns, primarily targeting US organizations. The AI-created code mimicked legitimate business documents and dashboards, making detection difficult and enabling credential theft and data breaches. Microsoft researchers identified the sophisticated use of AI as key to the attacks' success.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves an AI system (Microsoft Security Copilot identifying AI-generated code) used by attackers to develop sophisticated phishing malware. The malware's use directly caused harm by stealing login credentials and tracking users, fulfilling the criteria for an AI Incident. The AI's role in generating complex obfuscation was pivotal in enabling the phishing attack's success, leading to realized harm.[AI generated]
AI principles
AccountabilityPrivacy & data governanceRobustness & digital securitySafetyTransparency & explainability

Industries
Digital security

Affected stakeholders
WorkersBusiness

Harm types
Economic/PropertyReputationalHuman or fundamental rights

AI system task:
Content generation


Articles about this incident or hazard