Letsdatascience
Phishing Campaign Exploits Kuse.ai for Credential Harvesting
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On April 9, 2026, Trend Micro reported a phishing campaign leveraging Kuse.ai, an AI workplace app, to host malicious Markdown documents. Attackers utilized a Vendor Email Compromise (VEC) to send crafted emails that redirected users to a fake Microsoft login page. The phishing links appeared legitimate due to Kuse.ai's domain, which reduced suspicion among recipients. The campaign's tactics included using a blurred document preview and the uncommon .md file extension to evade detection. This incident highlights the risk of reputable platforms being exploited for phishing. Trend Micro's report did not include a statement from Kuse.ai regarding the incident. The attack primarily targets corporate users who may trust communications from known vendors.
Key Points: • Attackers exploited Kuse.ai's features to host phishing content. • The phishing method involved Vendor Email Compromise (VEC) tactics. • Use of a blurred preview and .md extension helped bypass security filters.