Inside an AI‑enabled device code phishing campaign
2026-04-06T20:52:24Z•22d56c93feee4b78af9e4e7620f4e1496142de716ccdce950216b984e8820fc7
AI‑enabled phishingAxiosLinux hosting tradecraftMFA bypassMedusa ransomwareMicrosoft DefenderOWASP Top 10 (agentic AI)Sapphire SleetStorm‑1175VBScript/MSI backdoorsWhatsApp malwareagentic AI riskscookie‑gated PHP webshellcritical infrastructure riskdevice‑code phishinghigh‑value asset protectionnpm compromisepost‑compromise accesssecure AI guidancesupply‑chain compromisevulnerable web‑facing assets
What happened
Microsoft Security Blog (Mar–Apr 2026) highlights multiple high-impact trends and campaigns: an AI‑enabled device‑code phishing campaign that dynamically generates live authentication codes to increase MFA bypass and sustain post‑compromise access; Storm‑1175’s high‑tempo Medusa ransomware operations that weaponize recently disclosed vulnerabilities against web‑facing assets; broad escalation in threat‑actor abuse of generative AI (higher phishing click‑through rates and industrialized MFA bypass); an Axios npm supply‑chain compromise attributed to North Korean actor Sapphire Sleet; stealthy,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 22d56c93feee4b78af9e4e7620f4e1496142de716ccdce950216b984e8820fc7
- Enrichment time
- 2026-04-06T20:52:24Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.