AI-Powered Gamma Platform Exploited in Sophisticated Phishing Attack Targeting Microsoft SharePoint Users

2 Sources

Share

Cybercriminals are leveraging Gamma, an AI-based presentation tool, to create convincing phishing campaigns that mimic Microsoft SharePoint login pages, highlighting the evolving tactics of threat actors in exploiting emerging technologies.

News article

AI-Powered Platform Exploited in Sophisticated Phishing Campaign

In a concerning development for cybersecurity, threat actors are now leveraging Gamma, an AI-powered presentation platform, to orchestrate sophisticated phishing attacks targeting Microsoft SharePoint users. Cybersecurity researchers from Abnormal Security have uncovered this new tactic, which demonstrates the evolving methods employed by cybercriminals to exploit emerging technologies

1

.

The Anatomy of the Attack

The phishing campaign begins with an email sent from compromised legitimate accounts, bypassing standard email authentication checks. The email contains a PDF attachment that, when clicked, redirects victims to a Gamma-hosted presentation. This presentation, featuring the impersonated organization's logo, prompts users to "Review Secure Documents"

2

.

Multi-Stage Redirection and Verification

Upon clicking the link in the Gamma presentation, users are taken through a series of carefully crafted steps:

  1. An intermediate page impersonating Microsoft
  2. A Cloudflare Turnstile verification step
  3. A final phishing page masquerading as a Microsoft SharePoint sign-in portal

This multi-stage approach serves to increase the attack's legitimacy and prevent automated URL analysis by security tools

1

.

Real-Time Credential Validation

The attackers have implemented a sophisticated system for real-time credential validation. If incorrect login information is provided, an "Incorrect password" error is triggered, indicating the use of an adversary-in-the-middle (AiTM) setup for immediate verification of stolen credentials

1

.

Exploiting Lesser-Known Tools

The use of Gamma, a relatively new AI-based presentation tool, in this attack chain is particularly noteworthy. As organizations become more familiar with phishing attacks exploiting well-known platforms like Dropbox or Google Drive, cybercriminals are turning to lesser-known tools to evade detection and exploit gaps in user awareness

2

.

The Rising Trend of AI-Driven Fraud

This incident is part of a broader trend of AI-driven fraud attacks, as highlighted in Microsoft's latest Cyber Signals report. Cybercriminals are increasingly using AI tools to generate believable content for attacks at scale, including deepfakes, voice cloning, and authentic-looking fake websites

1

.

Implications for Cybersecurity

This sophisticated phishing campaign underscores the need for organizations to stay vigilant and adapt their cybersecurity strategies. As attackers continue to exploit emerging technologies and lesser-known platforms, it becomes crucial for companies to update their security awareness training and implement robust multi-factor authentication systems to protect against evolving threats in the AI era.

Today's Top Stories

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo