Inside an AI‑enabled device code phishing campaign

2026-04-06T20:52:24Z22d56c93feee4b78af9e4e7620f4e1496142de716ccdce950216b984e8820fc7
AI‑enabled phishingAxiosLinux hosting tradecraftMFA bypassMedusa ransomwareMicrosoft DefenderOWASP Top 10 (agentic AI)Sapphire SleetStorm‑1175VBScript/MSI backdoorsWhatsApp malwareagentic AI riskscookie‑gated PHP webshellcritical infrastructure riskdevice‑code phishinghigh‑value asset protectionnpm compromisepost‑compromise accesssecure AI guidancesupply‑chain compromisevulnerable web‑facing assets

What happened

Microsoft Security Blog (Mar–Apr 2026) highlights multiple high-impact trends and campaigns: an AI‑enabled device‑code phishing campaign that dynamically generates live authentication codes to increase MFA bypass and sustain post‑compromise access; Storm‑1175’s high‑tempo Medusa ransomware operations that weaponize recently disclosed vulnerabilities against web‑facing assets; broad escalation in threat‑actor abuse of generative AI (higher phishing click‑through rates and industrialized MFA bypass); an Axios npm supply‑chain compromise attributed to North Korean actor Sapphire Sleet; stealthy,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
22d56c93feee4b78af9e4e7620f4e1496142de716ccdce950216b984e8820fc7
Enrichment time
2026-04-06T20:52:24Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.