{"id":7079,"date":"2025-09-20T10:04:10","date_gmt":"2025-09-20T10:04:10","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/20\/phishing-attacks-using-ai-powered-platforms-to-misleads-users-and-evades-security-tools\/"},"modified":"2025-09-20T10:04:10","modified_gmt":"2025-09-20T10:04:10","slug":"phishing-attacks-using-ai-powered-platforms-to-misleads-users-and-evades-security-tools","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/20\/phishing-attacks-using-ai-powered-platforms-to-misleads-users-and-evades-security-tools\/","title":{"rendered":"Phishing Attacks Using AI-Powered Platforms to Misleads Users and Evades Security Tools"},"content":{"rendered":"<p>    Phishing Attacks Using AI-Powered Platforms to Misleads Users and Evades Security Tools<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Phishing campaigns have long relied on social engineering to dupe unsuspecting users, but recent developments have elevated these attacks to a new level of sophistication.<\/p>\n<p>Attackers now harness advanced content-generation platforms to craft highly personalized emails and webpages, blending genuine corporate branding with contextually relevant messages.<\/p>\n<p>These platforms analyze public social media profiles, corporate press releases, and user activity to generate text that mirrors a victim\u2019s communication style, greatly increasing the likelihood of engagement.<\/p>\n<p>The resulting emails often bypass basic filters by avoiding known malicious keywords and employing dynamic content that changes with each delivery.<\/p>\n<p>At the same time, these platforms integrate real-time language models to refine phishing templates on the fly, adapting to evolving email defenses and user responses.<\/p>\n<p>This continuous learning loop allows campaigns to shift message templates within minutes, making static blocklists effectively obsolete.<\/p>\n<p>Trend Micro researchers <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/25\/i\/ai-development-platforms-enable-fake-captcha-pages.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> several clusters of these AI-enhanced phishing waves in August 2025, each targeting different industry verticals\u2014from financial services to healthcare\u2014demonstrating the breadth of the threat landscape.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgpjgANmXHWr0jrT2U9i9GVo8KdsVm0yWaiT20AYNXFh6JzQCq71__03_cH8faVFpnqinj_MO7ByviPKGYT4wbTwfJSTMgElfcSselVfgek5QRPnusKDwcYj7XFcpDPfgKyUyH4ObxcVuJdqMq_nyRLDxh6MiCmbvMPnuIu2HIAnzBmA42b3-Wpxto-TAc\/s16000\/Fake%2520captcha%2520page%2520%28Source%2520-%2520Trend%2520Micro%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Fake captcha page (Source \u2013 Trend Micro)<\/figcaption><\/figure>\n<\/div>\n<p>As organizations scramble to deploy heuristic and behavior-based filters, attackers counter with polymorphic payloads that mutate both text and embedded URLs in real-time.<\/p>\n<p>Beyond email, attackers leverage these platforms to generate convincing duplicate login portals hosted on cloud infrastructure, complete with valid SSL certificates and region-specific IP addresses.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhhqmPxmfzuZuiBE5DpthYVoLwhtZEaObeYj7I_vyw2rCAbsSe4kh04w_yQs8dHhAN-5HI6oXjxr_6yddBE-xvvPz8nv0dmevp3z0bc9aF7hhubqI7sZ4B61CQPd9C8XIMysxfnCee7hxNWC7TSi_ihnMnnuM4EW7YJ0VydnjGf2AbPmwkuKwviTWS56ro\/s16000\/Captcha%2520page%2520does%2520not%2520redirect%2520to%2520the%2520phishing%2520page%2520if%2520the%2520answer%2520is%2520incorrect%2520%28Source%2520-%2520Trend%2520Micro%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Captcha page does not redirect to the phishing page if the answer is incorrect (Source \u2013 Trend Micro)<\/figcaption><\/figure>\n<\/div>\n<p>The combination of genuine-looking domains, valid certificates, and personalized messaging leads many users to overlook subtle warning signs.<\/p>\n<p>Trend Micro analysts noted that such campaigns often include a brief authentication step mimicking multi-factor prompts, further reducing suspicion by aligning with standard corporate login flows.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhqhtQSgBqTDaaI-lb_ncjvj4NgZ043yAD0F0Kx8lte5Z-ys-IvFdIrJL6BCCoATBPMSmcrXLhP3xYLrJC3TxUkynkr_JQdq-pRilrLWkmGI8SsHNUQIencPEnw5OguMiJHGOZdlaU-RcZ3jqSXxMrQhamp3Okia0TkdAYqL2u6Hj1llO0fLrVrq6OBkPw\/s16000\/Phishing%2520page%2520after%2520the%2520captcha%2520is%2520solved%2520%28Source%2520-%2520Trend%2520Micro%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Phishing page after the captcha is solved (Source \u2013 Trend Micro)<\/figcaption><\/figure>\n<\/div>\n<p>Once credentials are harvested, follow-on <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> delivers a lightweight loader that contacts a command-and-control server over HTTPS, blending in with normal web traffic.<\/p>\n<p>In parallel with <a href=\"https:\/\/cybersecuritynews.com\/credential-theft-risks\/\" target=\"_blank\" rel=\"noreferrer noopener\">credential theft<\/a>, these campaigns deploy various evasion techniques within their code. Embedded scripts employ encryption and obfuscation routines to conceal their true purpose, only decrypting at runtime.<\/p>\n<p>The loader, written in PowerShell, leverages native Windows API calls to disable monitoring services before deploying the final payload.<\/p>\n<p>A representative snippet illustrates how the script resolves API functions dynamically:-<\/p>\n<pre class=\"wp-block-code\"><code>$kernel = Add-Type \u2013MemberDefinition @\"\n    [DllImport(\"kernel32.dll\")]\n    public static extern IntPtr GetProcAddress(IntPtr hModule, string procName);\n\"@ \u2013Name \"Kernel\" \u2013Namespace \"Win32\"\n$hMod = [Kernel]::GetModuleHandle(\"ntdll.dll\")\n$addr = [Kernel]::GetProcAddress($hMod, \"NtOpenProcess\")<\/code><\/pre>\n<h2 class=\"wp-block-heading\" id=\"h-evasion-techniques-and-detection-challenges\"><strong>Evasion Techniques and Detection Challenges<\/strong><\/h2>\n<p>A critical aspect of these AI-driven campaigns lies in their ability to evade signature-based and behavioral detection systems.<\/p>\n<p>The dynamically generated HTML payloads include randomized element IDs and inline style definitions that change with each interaction, rendering signature matching ineffective.<\/p>\n<p>On the network side, attacker-controlled domains employ fast <a href=\"https:\/\/cybersecuritynews.com\/how-to-use-passive-dns-to-trace-hackers-command-and-control-infrastructure\/\" target=\"_blank\" rel=\"noreferrer noopener\">flux DNS<\/a> to rotate authoritative name servers, while the malicious loader establishes encrypted tunnels over standard ports, camouflaging traffic among legitimate SSL connections.<\/p>\n<p>Endpoint sensors that rely on static heuristics are frequently bypassed as the loader disables Windows Event Logging for <a href=\"https:\/\/cybersecuritynews.com\/hackers-actively-exploiting-powershell\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell<\/a> execution, then reinstates logging settings once the secondary payload activates.<\/p>\n<p>This hit-and-run strategy leaves minimal forensic artifacts, complicating post-incident analysis and prolonging dwell time for threat actors.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Find this Story Interesting! Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/phishing-attacks-using-ai-powered-platforms\/\">Phishing Attacks Using AI-Powered Platforms to Misleads Users and Evades Security Tools<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/phishing-attacks-using-ai-powered-platforms\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Phishing Attacks Using AI-Powered Platforms to Misleads Users and Evades Security Tools Phishing campaigns have long relied on social engineering to dupe unsuspecting users, but recent developments have elevated these attacks to a new level of sophistication. Attackers now harness advanced content-generation platforms to craft highly personalized emails and webpages, blending genuine corporate branding with [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-7079","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7079"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7079"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7079\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7079"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7079"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7079"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}