AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification

AI-Enabled Social Engineering and Synthetic Media (TL-2026-2774), also tracked as Synthetic Media Social Engineering, is a high-severity phishing campaign, first published 2026-09-29. It has no confirmed attribution, affects Microsoft Microsoft 365 / Entra ID (OAuth 2.0 device authorization, maps to 14 MITRE ATT&CK techniques (T1078.004, T1087.004, T1098.005), and is covered by 9 detection rules and 26 indicators of compromise.

Key facts for TL-2026-2774

Threat ID
TL-2026-2774
Also known as
Synthetic Media Social Engineering, Deepfake-Enabled Fraud
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-09-29
Last reviewed
2026-09-29
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
finance, government administration, engineering, logistics, human-resources, cryptocurrency
Target regions
Global, North America, Europe, Asia
Detection rules
9
Indicators of compromise
26

Malware and tooling in AI-Enabled Social Engineering and Synthetic Media

Malware and tooling: telegram, zgRAT, EvilTokens, FraudGPT, GhostGPT, KawaiiGPT, Tycoon, WormGPT4, Xanthorox

Recorded Future's Insikt Group reports escalating AI-enabled social engineering: AI-enhanced phishing (malicious LLMs, EvilTokens device-code PhaaS, AI site builders) is largely countered by existing defenses, but synthetic media (voice cloning, live video deepfakes, biometric injection) erodes the audiovisual and biometric signals organizations use to verify identity. Documented losses include Arup (~$25M, Feb 2024) and a Singapore deepfake Zoom fraud (~SGD 4.9M, May 2026).

How AI-Enabled Social Engineering and Synthetic Media works

Insikt Group's 'Social Engineering in the Age of Synthetic Media' distinguishes two problems. First, AI-enhanced phishing: generative AI produces personalized lures, fraudulent login pages and automated follow-ups, and is packaged in underground offerings. The report names malicious LLMs (WormGPT, WormGPT4, EscapeGPT, FraudGPT, WolfGPT, DarkGPT, BlackhatGPT, KawaiiGPT, Nytheon, Xanthorox, GhostGPT, SheByte) and the EvilTokens phishing-as-a-service kit (emerged April 2026 per the report), which combines AI-generated lures, account validation, customizable infrastructure and automated creation of fresh device sign-in codes. The report also notes abuse of legitimate AI tooling, such as the Lovable AI website builder used to stand up large numbers of sites impersonating Microsoft, UPS and HR/financial platforms (August 2025), and open-weight models (GLM-5.2, Kimi, DeepSeek, Qwen, HUIHUI-AI reportedly used by the Gentlemen ransomware group). Insikt's assessment is that most of this can still be handled with existing defenses: email/web filtering, phishing-resistant MFA, monitoring for anomalous sign-ins, new inbox rules and unexpected permissions, and session revocation.

Second, synthetic media is the exception. Voice cloning of executives and officials, live video-call impersonation and falsified identity documents weaken the trust signals people and identity-verification vendors depend on. Facial biometric injection inserts AI-generated faces into video streams through virtual cameras or modified software, and screen-replay videos of synthetic blinking are used to pass liveness checks. Group-IB-recorded data cited by the report shows 8,065 biometric bypass attempts at an unnamed financial institution between January and August 2025; Telegram groups sell deepfake bypass tools aimed at platforms such as Binance, BBVA and Revolut. Human and automated detection is unreliable: a 2024 study put human identification accuracy of synthetic image/audio/video at 51.2%, and a May 2026 study found deepfake detectors only slightly better than chance.

Case studies: in February 2024 an Arup employee joined a video call with deepfaked CFO and colleagues and made 15 transfers to five Hong Kong accounts (~HK$200M / US$25M); no Arup systems were breached. In May 2026 a Singapore professional was contacted on WhatsApp by someone posing as the Secretary to the Cabinet, signed an NDA, joined a fabricated Zoom meeting with deepfaked senior officials, and transferred at least SGD 4.9M after a follow-up from a fake lawyer; Singapore Police cited poor lip-sync, distorted backgrounds, obscured Zoom logos and audio routed through a single account as tell-tale signs. The FBI has warned since 2023 (updated 19 Dec 2025) of smishing and AI voice-clone vishing impersonating senior US officials, moving victims to encrypted messaging apps.

Supporting technical reporting on EvilTokens (Microsoft, 6 Apr 2026; Abnormal, 3 Apr 2026; Sekoia, March 2026) shows the device-code flow being abused so victims complete real MFA on Microsoft infrastructure while the attacker captures OAuth tokens, then registers devices for Primary Refresh Tokens, creates inbox rules, performs Microsoft Graph reconnaissance and mines mailboxes for payment threads. The source report itself lists no IOCs and no nation-state attribution; the IOCs below come from the cited vendor reports.

MITRE ATT&CK techniques used in TL-2026-2774

Initial Access

T1078.004 Valid Accounts: Cloud Accounts; T1566.002 Phishing: Spearphishing Link; T1566.004 Phishing: Spearphishing Voice

Discovery

T1087.004 Account Discovery: Cloud Account

Persistence

T1098.005 Account Manipulation: Device Registration

Collection

T1114.003 Email Collection: Email Forwarding Rule

Execution

T1204.001 User Execution: Malicious Link

Credential Access

T1528 Steal Application Access Token

lateral-movement

T1550.001 Use Alternate Authentication Material: Application Access Token

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services; T1588.007 Obtain Capabilities: Artificial Intelligence

Impact

T1657 Financial Theft

Defense Evasion

T1684.001 Impersonation

Affected products and versions in AI-Enabled Social Engineering and Synthetic Media

  • Microsoft — Microsoft 365 / Entra ID (OAuth 2.0 device authorization grant)
    Vulnerable versions: Tenants permitting device code flow
  • Various — Biometric identity-verification and liveness-check systems (KYC)
    Vulnerable versions: Systems lacking injection-attack detection
  • Various — Video-conferencing and voice-based approval workflows (e.g. Zoom)
    Vulnerable versions: Processes relying on audiovisual recognition for authorization

Remediation for AI-Enabled Social Engineering and Synthetic Media

Immediate actions

  • Require out-of-band verification (call a known number or use an approved system) for unusual, urgent or sensitive requests, including those apparently from senior leaders
  • Require an independent second approver for large payments, payroll changes, new access, account recovery and contact-detail changes
  • Revoke active sessions/refresh tokens and reset credentials after suspected device-code or AiTM phishing compromise
  • Hunt for unexpected inbox rules, new device registrations and unusual OAuth device-code sign-ins

Workarounds

  • Block OAuth device code flow via Conditional Access where it is not required
  • Apply Safe Links and anti-phishing policies; strong email and web filtering
  • Configure sign-in risk policies with conditional re-authentication

Longer-term hardening

  • Deploy phishing-resistant MFA (FIDO2 / passkeys)
  • Use deepfake detection only alongside independent verification procedures, not as a sole control
  • Deploy secure identity-capture with injection-attack and virtual-camera detection in KYC/liveness flows
  • Include current AI-generated lure examples in security awareness training and teach that polished, personalized messages are not proof of legitimacy

Timeline of AI-Enabled Social Engineering and Synthetic Media

  • Arup employee transfers ~US$25M (HK$200M) in 15 transfers to five Hong Kong accounts after a video call with deepfaked CFO and colleagues (month-level date; publicly disclosed May 2024).
  • Start of the Jan-Aug 2025 window in which 8,065 biometric bypass attempts were recorded at an unnamed financial institution (Group-IB data cited by Insikt).
  • Storm-2372 device code phishing activity (February 2025), the precursor to the AI-enabled EvilTokens escalation per Microsoft.
  • Proofpoint publishes research on cybercriminal abuse of the Lovable AI website builder for phishing, credential theft and malware delivery.
  • FBI IC3 updates its PSA on smishing and AI voice-clone vishing impersonating senior US officials (activity since 2023).
  • EvilTokens PhaaS circulating in underground communities since mid-February 2026 (per Sekoia via secondary reporting).
  • Abnormal AI publishes analysis of EvilTokens: device-code OAuth abuse, MailVault webmail client and AI-driven mailbox analysis.
  • Microsoft Defender Security Research publishes the AI-enabled device code phishing campaign report tied to EvilTokens.
  • Singapore Police advisory on deepfake Zoom scam impersonating the PM and senior officials; at least SGD 4.9M transferred by one victim (advisory dated 14-16 May 2026 across sources).
  • Open-weight GLM-5.2 release draws reporting on potential abuse by threat actors (Axios), cited by Insikt.

Sources cited for AI-Enabled Social Engineering and Synthetic Media

More in phishing

Detection coverage for TL-2026-2774

As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2774 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats