4 Sources
[1]
Be Careful With Facebook Ads for AI Video Generators: They Could Be Malware
Cybercriminals have been posting Facebook ads for fake AI video generators to distribute malware, Google's threat intelligence unit Mandiant reports. The campaign aims to lure social media users into visiting malicious websites. It begins with ads impersonating legitimate AI video generator tools
[2]
Warning: Facebook Ads for AI Video Generators Might Be Malware
AI video generators have exploded in popularity, allowing users to create videos they never could have recorded in the real world. Along with millions of users who are using these legitimate apps, cybercriminals have also taken note and flooded Facebook with malicious ads that send people to fake
[3]
Millions of users could fall for fake Facebook ad for a text-to-AI-video tool that is just malware
Google's Mandiant Threat Defense group has identified a campaign, tracked as UNC6032, which "weaponizes the interest around AI tools" - specifically tools used to generate videos based on user prompts. Mandiant experts identified thousands of postings of fake "AI video generator" websites that
[4]
Fake AI Tools Lure Social Media Users In Global Malware Scam
Cybercriminals are exploiting the booming interest in artificial intelligence (AI) tools to spread malware through fake ads on Facebook and LinkedIn, a new report has revealed. According to cybersecurity firm Mandiant, a Vietnam-linked hacking group is behind a widespread scam that uses
Share
Copy Link
Cybercriminals are using fake Facebook ads for AI video generators to spread malware, potentially affecting millions of users. The campaign, linked to a Vietnam-based group, impersonates legitimate AI tools to lure victims.
In a concerning development at the intersection of artificial intelligence and cybersecurity, a widespread malware campaign has been uncovered that exploits the growing interest in AI tools. Cybercriminals are leveraging fake Facebook ads for AI video generators to distribute malware, potentially affecting millions of users worldwide
1
.
Source: PC Magazine
Google's threat intelligence unit, Mandiant, has identified and tracked this malicious campaign under the name UNC6032. The operation, which has been active since mid-2024, is believed to have links to a Vietnam-based group
2
. The cybercriminals behind UNC6032 have been posting ads on social media platforms, primarily Facebook and to a lesser extent LinkedIn, that impersonate legitimate AI video generator tools such as Luma AI, Canva Dream Lab, and Kling AI3
.The attackers create convincing ads that, when clicked, redirect users to malicious websites. These fake sites then deploy various malware payloads, including Python-based infostealers and backdoors
1
. To evade detection by Meta (Facebook's parent company), the cybercriminals constantly modify their domains and publish new ads daily.The scale of this operation is significant. Mandiant's investigation revealed ads for over 30 malicious websites, with a sample of 120 ads in the EU alone reaching over 2.3 million users
2
. This extensive reach underscores the potential impact of the campaign on both individual users and organizations.The malware deployed in this campaign, known as STARKVEIL, is capable of stealing a wide range of sensitive information, including:
4
Both Meta and LinkedIn have been alerted to the campaign and have taken steps to combat it. Meta had already detected and removed a significant number of malicious ads before being notified by Mandiant in 2024
1
. However, the persistent nature of the threat means that new malicious ads and websites continue to appear daily.Related Stories

Source: TechRadar
To protect against this and similar threats, cybersecurity experts advise users to:
2
This malware campaign highlights a growing trend in cybercrime where attackers exploit popular technology trends to deceive users. As AI continues to gain prominence, it's likely that similar scams will emerge, targeting both individuals and organizations attracted by the promise of cutting-edge AI capabilities
4
.The incident serves as a reminder of the need for continued vigilance in the digital space, especially as new technologies capture public imagination and attention. As Yash Gupta, a senior manager at Mandiant, noted, "Criminals go where the attention is. Right now, that's AI."
4
Summarized by
Navi
[3]
12 May 2025•Technology

19 Nov 2024•Technology

30 May 2025•Technology
