Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New Phishing Kit with AI-assisted Development Attacking Microsoft Users to Steal Logins

A phishing operation targeting Microsoft Outlook users has been identified, utilizing a sophisticated kit with AI-assisted development since March 2025. This campaign, characterized by a unique signature featuring four mushroom emojis within the string…

A phishing operation targeting Microsoft Outlook users has been identified, utilizing a sophisticated kit with AI-assisted development since March 2025. This campaign, characterized by a unique signature featuring four mushroom emojis within the string "OUTL," has been observed across more than 75 deployments.

The operation captures email credentials, IP addresses, and geolocation data, exfiltrating this information through Telegram bots and Discord webhooks. The phishing kit replicates the Microsoft Outlook login interface with Spanish language prompts, offering a convincing page to unsuspecting victims.

Upon entry of credentials, the kit enriches the captured data with contextual information by querying external APIs for IP resolution and geolocation details in real time before transmitting the data to attackers.

A phishing operation targeting Microsoft Outlook users has been identified, utilizing a sophisticated kit with AI-assisted development since March 2025.
Madison Drake · Thehackingpost

Technical Analysis of the Infection Mechanism

The phishing kit employs a modular architecture where configuration data is distinct from execution logic. Early versions utilized a script named xjsx.js to store Telegram bot tokens and chat IDs with light obfuscation. When a user submits credentials through the fake login form, the kit validates the email format and gathers IP and location information via external APIs.

The exfiltration payload follows a standardized format, transmitting data such as email, password, IP address, and location details via HTTPS POST requests to Telegram or Discord endpoints. The transition to Discord webhooks represents a strategic evolution, as these channels limit access to historical exfiltration data.

Advertisement

The kit's infrastructure analysis suggests a service-oriented model, indicating a potential phishing-as-a-service operation where different operators may utilize the same toolkit.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories