Models
September 24, 2025

Microsoft flags AI-driven phishing: LLM-crafted SVG files outsmart email security

Microsoft uncovered phishing attacks using SVG files with embedded, AI-generated JavaScript obfuscated via business language. The technique evaded many email filters, marking a risky evolution in cyber threats.

Microsoft disclosed a phishing campaign from August 28 that used SVG files containing embedded JavaScript code, obfuscated via business-term encodings to appear benign and bypass filters.

Attackers disguised the payload by embedding terms like “revenue” or “shares” into invisible SVG elements. The files were presented as PDFs to lure recipients into opening them.

Microsoft’s analysis suggests the code was generated (or assisted) by a large language model (LLM), given stylistic artifacts, verbosity, and structural patterns uncommon in hand-written code. The campaign emphasizes how AI is being weaponized to craft more deceptive cyberattacks, requiring defenders to evolve detection methods.

#
Anthropic

Read Our Content

See All Blogs
AWS

The Complete Guide to Nova 2 Omni

Sharan Sundar Sankaran

December 14, 2025
Read more
AWS

Day 4 at AWS re:Invent: Experience-Based Acceleration (EBA) partners announced and a big bang close

Deveshi Dabbawala

December 4, 2025
Read more