AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification
AI-Enabled Social Engineering and Synthetic Media (TL-2026-2774), also tracked as Synthetic Media Social Engineering, is a high-severity phishing campaign, first published 2026-09-29. It has no confirmed attribution, affects Microsoft Microsoft 365 / Entra ID (OAuth 2.0 device authorization, maps to 14 MITRE ATT&CK techniques (T1078.004, T1087.004, T1098.005), and is covered by 9 detection rules and 26 indicators of compromise.
Key facts for TL-2026-2774
- Threat ID
- TL-2026-2774
- Also known as
- Synthetic Media Social Engineering, Deepfake-Enabled Fraud
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-09-29
- Last reviewed
- 2026-09-29
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- finance, government administration, engineering, logistics, human-resources, cryptocurrency
- Target regions
- Global, North America, Europe, Asia
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in AI-Enabled Social Engineering and Synthetic Media
Malware and tooling: telegram, zgRAT, EvilTokens, FraudGPT, GhostGPT, KawaiiGPT, Tycoon, WormGPT4, Xanthorox
Recorded Future's Insikt Group reports escalating AI-enabled social engineering: AI-enhanced phishing (malicious LLMs, EvilTokens device-code PhaaS, AI site builders) is largely countered by existing defenses, but synthetic media (voice cloning, live video deepfakes, biometric injection) erodes the audiovisual and biometric signals organizations use to verify identity. Documented losses include Arup (~$25M, Feb 2024) and a Singapore deepfake Zoom fraud (~SGD 4.9M, May 2026).
How AI-Enabled Social Engineering and Synthetic Media works
Insikt Group's 'Social Engineering in the Age of Synthetic Media' distinguishes two problems. First, AI-enhanced phishing: generative AI produces personalized lures, fraudulent login pages and automated follow-ups, and is packaged in underground offerings. The report names malicious LLMs (WormGPT, WormGPT4, EscapeGPT, FraudGPT, WolfGPT, DarkGPT, BlackhatGPT, KawaiiGPT, Nytheon, Xanthorox, GhostGPT, SheByte) and the EvilTokens phishing-as-a-service kit (emerged April 2026 per the report), which combines AI-generated lures, account validation, customizable infrastructure and automated creation of fresh device sign-in codes. The report also notes abuse of legitimate AI tooling, such as the Lovable AI website builder used to stand up large numbers of sites impersonating Microsoft, UPS and HR/financial platforms (August 2025), and open-weight models (GLM-5.2, Kimi, DeepSeek, Qwen, HUIHUI-AI reportedly used by the Gentlemen ransomware group). Insikt's assessment is that most of this can still be handled with existing defenses: email/web filtering, phishing-resistant MFA, monitoring for anomalous sign-ins, new inbox rules and unexpected permissions, and session revocation.
Second, synthetic media is the exception. Voice cloning of executives and officials, live video-call impersonation and falsified identity documents weaken the trust signals people and identity-verification vendors depend on. Facial biometric injection inserts AI-generated faces into video streams through virtual cameras or modified software, and screen-replay videos of synthetic blinking are used to pass liveness checks. Group-IB-recorded data cited by the report shows 8,065 biometric bypass attempts at an unnamed financial institution between January and August 2025; Telegram groups sell deepfake bypass tools aimed at platforms such as Binance, BBVA and Revolut. Human and automated detection is unreliable: a 2024 study put human identification accuracy of synthetic image/audio/video at 51.2%, and a May 2026 study found deepfake detectors only slightly better than chance.
Case studies: in February 2024 an Arup employee joined a video call with deepfaked CFO and colleagues and made 15 transfers to five Hong Kong accounts (~HK$200M / US$25M); no Arup systems were breached. In May 2026 a Singapore professional was contacted on WhatsApp by someone posing as the Secretary to the Cabinet, signed an NDA, joined a fabricated Zoom meeting with deepfaked senior officials, and transferred at least SGD 4.9M after a follow-up from a fake lawyer; Singapore Police cited poor lip-sync, distorted backgrounds, obscured Zoom logos and audio routed through a single account as tell-tale signs. The FBI has warned since 2023 (updated 19 Dec 2025) of smishing and AI voice-clone vishing impersonating senior US officials, moving victims to encrypted messaging apps.
Supporting technical reporting on EvilTokens (Microsoft, 6 Apr 2026; Abnormal, 3 Apr 2026; Sekoia, March 2026) shows the device-code flow being abused so victims complete real MFA on Microsoft infrastructure while the attacker captures OAuth tokens, then registers devices for Primary Refresh Tokens, creates inbox rules, performs Microsoft Graph reconnaissance and mines mailboxes for payment threads. The source report itself lists no IOCs and no nation-state attribution; the IOCs below come from the cited vendor reports.
MITRE ATT&CK techniques used in TL-2026-2774
Initial Access
T1078.004 Valid Accounts: Cloud Accounts; T1566.002 Phishing: Spearphishing Link; T1566.004 Phishing: Spearphishing Voice
Discovery
T1087.004 Account Discovery: Cloud Account
Persistence
T1098.005 Account Manipulation: Device Registration
Collection
T1114.003 Email Collection: Email Forwarding Rule
Execution
T1204.001 User Execution: Malicious Link
Credential Access
T1528 Steal Application Access Token
lateral-movement
T1550.001 Use Alternate Authentication Material: Application Access Token
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services; T1588.007 Obtain Capabilities: Artificial Intelligence
Impact
Defense Evasion
Affected products and versions in AI-Enabled Social Engineering and Synthetic Media
- Microsoft — Microsoft 365 / Entra ID (OAuth 2.0 device authorization grant)
Vulnerable versions: Tenants permitting device code flow - Various — Biometric identity-verification and liveness-check systems (KYC)
Vulnerable versions: Systems lacking injection-attack detection - Various — Video-conferencing and voice-based approval workflows (e.g. Zoom)
Vulnerable versions: Processes relying on audiovisual recognition for authorization
Remediation for AI-Enabled Social Engineering and Synthetic Media
Immediate actions
- Require out-of-band verification (call a known number or use an approved system) for unusual, urgent or sensitive requests, including those apparently from senior leaders
- Require an independent second approver for large payments, payroll changes, new access, account recovery and contact-detail changes
- Revoke active sessions/refresh tokens and reset credentials after suspected device-code or AiTM phishing compromise
- Hunt for unexpected inbox rules, new device registrations and unusual OAuth device-code sign-ins
Workarounds
- Block OAuth device code flow via Conditional Access where it is not required
- Apply Safe Links and anti-phishing policies; strong email and web filtering
- Configure sign-in risk policies with conditional re-authentication
Longer-term hardening
- Deploy phishing-resistant MFA (FIDO2 / passkeys)
- Use deepfake detection only alongside independent verification procedures, not as a sole control
- Deploy secure identity-capture with injection-attack and virtual-camera detection in KYC/liveness flows
- Include current AI-generated lure examples in security awareness training and teach that polished, personalized messages are not proof of legitimacy
Timeline of AI-Enabled Social Engineering and Synthetic Media
- Arup employee transfers ~US$25M (HK$200M) in 15 transfers to five Hong Kong accounts after a video call with deepfaked CFO and colleagues (month-level date; publicly disclosed May 2024).
- Start of the Jan-Aug 2025 window in which 8,065 biometric bypass attempts were recorded at an unnamed financial institution (Group-IB data cited by Insikt).
- Storm-2372 device code phishing activity (February 2025), the precursor to the AI-enabled EvilTokens escalation per Microsoft.
- Proofpoint publishes research on cybercriminal abuse of the Lovable AI website builder for phishing, credential theft and malware delivery.
- FBI IC3 updates its PSA on smishing and AI voice-clone vishing impersonating senior US officials (activity since 2023).
- EvilTokens PhaaS circulating in underground communities since mid-February 2026 (per Sekoia via secondary reporting).
- Abnormal AI publishes analysis of EvilTokens: device-code OAuth abuse, MailVault webmail client and AI-driven mailbox analysis.
- Microsoft Defender Security Research publishes the AI-enabled device code phishing campaign report tied to EvilTokens.
- Singapore Police advisory on deepfake Zoom scam impersonating the PM and senior officials; at least SGD 4.9M transferred by one victim (advisory dated 14-16 May 2026 across sources).
- Open-weight GLM-5.2 release draws reporting on potential abuse by threat actors (Axios), cited by Insikt.
Sources cited for AI-Enabled Social Engineering and Synthetic Media
- Social Engineering in the Age of Synthetic Media (Recorded Future Insikt Group)
- AI-enabled device code phishing campaign (Microsoft Defender Security Research)
- EvilTokens: Turning OAuth Device Codes into Full-Scale BEC Operations (Abnormal AI)
- Cybercriminals abuse AI website creation app for phishing (Proofpoint)
- FBI IC3 PSA: Impersonation of senior US officials
- Singapore Police Force advisory on scams impersonating senior government officials
- Deepfake Zoom scam impersonates Singapore PM (Sumsub)
- UK-Based Arup Loses $25 Million in Deepfake Video Conference Scam (FinTelegram)
- The Dilemma of AI: Malicious LLMs (Unit 42)
- Threat actor usage of AI tools (Google Cloud Threat Intelligence)
- WormGPT: New AI tool allows cybercriminals (The Hacker News)
- Cyberscammers bypassing bank verification via Telegram (MIT Technology Review)
More in phishing
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations
- Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+ Organizations
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access
- Fake American Express "non-compliance" card-lock phishing campaign targets Australians
- Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt Injection)
Detection coverage for TL-2026-2774
As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2774 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.