INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Lazarus Group Deploys AI-Powered Phishing Tool for Widescale Credential Theft

| 2026-09-08 12:03 CRITICAL HIGH AI-ENABLED ATTACK PHISHING & SOCIAL ENGINEERING STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
Hackers have built AI frameworks for widescale credential theft, targeting countries in the TARGET_REGION. The attackers are believed to be China-linked cyberespionage actors, with other groups such as Russia-based UNC5792 also using AI models to automate monitoring bots searching Telegram channels for information of interest to their governments. These attacks affect multiple sectors, including government and public services, with a reported breach of Florida's "DAVID" DMV database attributed to the ShinyHunters hackers. The attackers use an AI-assisted, automated exploitation and post-exploitation pipeline to steal credentials, which is then used for widescale credential theft. As of now, no further information on the current status of these attacks has been reported.
Technical Mitigations AI-generated
• Patch Microsoft September 2026 Patch Tuesday fixes, specifically addressing the two zero-days. • Detect and block ShinyHunters' use of fake shops to steal credit cards by monitoring MageCart traffic. • Implement age-awareness APIs in Windows applications to detect if users are children, teens, or adults.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

bi•••@bl•••.•••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
bi•••••.toulas
ad•••••.com
ww•••••.com
de•••••.com
10•••••.jpg
10•••••.jpg
10•••••.jpg
10•••••.png
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
TeamPCPTeamPCPShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎2016 August
Threat actors exploited vulnerabilities in August 2016 updates for Windows Server 2016 to trigger a specific error code, potentially leading to widescale credential theft.
infrastructure Windows
tactic T1584.004 - Server
infrastructure 2016 Windows Server
‎September 2026
Microsoft released a September 2026 Patch Tuesday that addressed 966 flaws, including two zero-days.
organisation Microsoft
general_metric 966 flaws
general_metric 2 days
‎September 8, 2026
Threat actors used an AI coding chatbot and markdown agent instructions to build, deploy, and execute a mass credential-harvesting campaign in under six hours.
organisation ThreatLocker
data_breach 0 September
infrastructure Windows
organisation Google
organisation API
threat_actor TeamPCP
organisation Gemini AI
organisation The Blue Report 2026
organisation EU CRA
‎2003 - 2026
Threat actors utilized the website's advertising and social media features to build AI frameworks for widescale credential theft.
organisation Social & Feeds
‎2026/09/08
Threat actors have integrated AI capabilities into multiple stages of an attack lifecycle, including reconnaissance, phishing, malware development, exploitation, post-exploitation, and data processing.
organisation Webinar
organisation Recon
infrastructure Microsoft 365
organisation BigBear Microsoft 365
organisation MFA
victims 258 organizations
organisation CLI
organisation JadePuffer
organisation Claude
organisation Chrome
infrastructure Linux
organisation infosec news
organisation APM
organisation Hackers
infrastructure Windows
organisation Stack Protection
organisation Windows Registry
organisation the Windows Registry
organisation Magento
organisation Adobe
threat_actor ShinyHunters
organisation DMV
organisation DoppelCart
organisation IP
organisation safely.jpg
organisation LLM
organisation CTI
organisation Upcoming Webinar
organisation ClickFix
organisation Freestar.com
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Microsoft 365
Affected Product
Metrics
victims
258
Organizations
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
2,016
Windows Server
Metrics
data_breach
0
September
Intelligence Sources
BleepingComputer 2026-09-08