Phishing Campaign Exploits Kuse.ai for Credential Harvesting

Phishing Campaign Exploits Kuse.ai for Credential Harvesting

First seen 19 May 2026, 17:24 UTC Blog.Knowbe4Letsdatascience 78% similarity 58.5

Article Content

Browse articles
ThreatCluster

On April 9, 2026, Trend Micro reported a phishing campaign leveraging Kuse.ai, an AI workplace app, to host malicious Markdown documents. Attackers utilized a Vendor Email Compromise (VEC) to send crafted emails that redirected users to a fake Microsoft login page. The phishing links appeared legitimate due to Kuse.ai's domain, which reduced suspicion among recipients. The campaign's tactics included using a blurred document preview and the uncommon .md file extension to evade detection. This incident highlights the risk of reputable platforms being exploited for phishing. Trend Micro's report did not include a statement from Kuse.ai regarding the incident. The attack primarily targets corporate users who may trust communications from known vendors.

Key Points: • Attackers exploited Kuse.ai's features to host phishing content. • The phishing method involved Vendor Email Compromise (VEC) tactics. • Use of a blurred preview and .md extension helped bypass security filters.

ThreatCluster AI

Timeline

2026-04-09
Phishing campaign identified
Trend Micro reported a phishing campaign using Kuse.ai to host malicious Markdown documents, targeting corporate credentials.
Letsdatascience
2026-04-09
Vendor Email Compromise initiated
Attackers compromised a vendor mailbox to send crafted emails leading to phishing links on Kuse.ai.
Letsdatascience
2026-05-19
Public warning issued
KnowBe4 and other sources reported on the phishing campaign, raising awareness about the abuse of Kuse.ai.
Blog.Knowbe4

Community

Browse all →

Tracked Entities in This Story