Summary: Threat actors are using the AI-powered presentation platform Gamma to conduct sophisticated phishing attacks that deceive users into submitting their Microsoft credentials through a multi-stage redirection process. The attack begins with a phishing email containing a disguised PDF that ultimately leads victims to a spoofed Microsoft login page. This method capitalizes on legitimate services to bypass traditional email authentication measures and evade detection tools.
Affected: Microsoft and its users
Keypoints :
- Attackers leverage Gamma to create fraudulent presentations that lead to Microsoft credential harvesting.
- Phishing emails often come from compromised legitimate accounts, making the initial contact appear trustworthy.
- Multi-stage redirection incorporates CAPTCHAs to obstruct automated analysis, complicating detection efforts.
- This trend reflects a growing sophistication in phishing tactics, utilizing legitimate tools to exploit vulnerabilities.
- Microsoft warns about the rise of AI-driven fraud that enhances the effectiveness of social engineering attacks.
Source: https://thehackernews.com/2025/04/ai-powered-gamma-used-to-host-microsoft.html