New Phishing Kit with AI-assisted Development Attacking Microsoft Users to Steal Logins
ID: cda426b3-7acc-5419-90c9-09f5ae0c284a
STIX ID: report--cda426b3-7acc-5419-90c9-09f5ae0c284a
Feed Name: cybersecurityNews.com
A Spanish-language phishing campaign impersonating Microsoft Outlook (tracked by a distinctive mushroom-emoji "OUTL" signature) has been active since March 2025, deploying a modular credential-harvesting kit observed in 75+ deployments. The kit validates submitted credentials, enriches them with IP and geolocation data via external APIs, and exfiltrates standardized payloads to attackers using Telegram bots and Discord webhooks; multiple obfuscation variants and an AI-like clean code variant (disBLOCK.js) indicate evolving, service-oriented operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
