3 Sources
[1]
Crims defeat human intelligence with fake AI installers
Take care when downloading AI freebies, researcher tells The Register Criminals are using installers for fake AI software to distribute ransomware and other destructive malware. Cisco Talos recently uncovered three of these threats, which use legit-looking websites whose domain names vary the
[2]
Cybercriminals Target AI Users with Malware-Loaded Installers Posing as Popular Tools
Fake installers for popular artificial intelligence (AI) tools like OpenAI ChatGPT and InVideo AI are being used as lures to propagate various threats, such as the CyberLock and Lucky_Gh0$t ransomware families, and a new malware dubbed Numero. "CyberLock ransomware, developed using PowerShell,
[3]
Cybercriminals exploit AI hype to spread ransomware, malware
Threat actors linked to lesser-known ransomware and malware projects now use AI tools as lures to infect unsuspecting victims with malicious payloads. This development follows a trend that has been growing since last year, starting with advanced threat actors using deepfake content generators to
Share
Copy Link
Threat actors are using fake AI tool installers to distribute ransomware and malware, targeting individuals and businesses interested in AI technologies.
In a concerning development, cybercriminals are capitalizing on the growing interest in artificial intelligence (AI) to distribute ransomware and other malicious software. Cisco Talos researchers have uncovered a trend where threat actors are using fake installers for popular AI tools as a means to infect unsuspecting users with various malware
1
.
Source: Hacker News
Three primary threats have been identified:
CyberLock Ransomware: Distributed through a fake AI solution website impersonating NovaLeads, a legitimate lead monetization platform. The malware encrypts files and demands a $50,000 ransom in Monero cryptocurrency
2
.Lucky_Gh0$t Ransomware: A variant of the Yashma ransomware, disguised as a ChatGPT installer. It targets files smaller than 1.2GB for encryption and deletes larger files
3
.Numero Malware: A previously unknown destructive malware that poses as an InVideo AI installer. It corrupts the Windows GUI, rendering the system unusable
1
.The cybercriminals employ various methods to distribute their malicious software:
1
.2
.3
.
Source: BleepingComputer
The primary targets appear to be individuals and organizations in the B2B sales and marketing sectors, where AI tools are gaining popularity. Chetan Raghuprasad, a Cisco Talos researcher, stated, "Individuals, small-scale businesses, startups, and other users in established business sectors should evaluate the sources of the AI tools they download and install on their machines to avoid falling prey to such threats"
1
.Related Stories
This trend is part of a larger pattern of cybercriminals exploiting emerging technologies. Google-owned Mandiant has also reported on a malvertising campaign attributed to a Vietnam-based threat group, UNC6032, which has been active since mid-2024
2
.
Source: The Register
To protect against these threats, cybersecurity experts recommend:
As the AI hype continues to grow, users must remain vigilant and prioritize cybersecurity when exploring new AI technologies.
Summarized by
Navi
[1]
[2]
[3]
04 Sept 2025•Technology

12 May 2025•Technology

19 Nov 2024•Technology

1
Science and Research

2
Policy and Regulation

3
Technology