logo

New Phishing Kit with AI-assisted Development Attacking Microsoft Users to Steal Logins

ID: cda426b3-7acc-5419-90c9-09f5ae0c284a

STIX ID: report--cda426b3-7acc-5419-90c9-09f5ae0c284a

Feed Name: cybersecurityNews.com

Threat Score
68/100

Date Published: 2025-12-29

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A Spanish-language phishing campaign impersonating Microsoft Outlook (tracked by a distinctive mushroom-emoji "OUTL" signature) has been active since March 2025, deploying a modular credential-harvesting kit observed in 75+ deployments. The kit validates submitted credentials, enriches them with IP and geolocation data via external APIs, and exfiltrates standardized payloads to attackers using Telegram bots and Discord webhooks; multiple obfuscation variants and an AI-like clean code variant (disBLOCK.js) indicate evolving, service-oriented operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.