Moneycontrol PRO
HomeTechnologyAI scams: Google explains how hackers are using AI-powered tools to dupe you; shares tips to stay safe

AI scams: Google explains how hackers are using AI-powered tools to dupe you; shares tips to stay safe

Hackers are exploiting AI’s popularity by creating fake websites and video generators to steal user data and money. Google revealed that cybercriminals, linked to Vietnam, are running global scams via social media ads that mimic AI tools.

June 01, 2025 / 10:43 IST
AI scams

Cybercriminals are capitalising on the global interest in artificial intelligence (AI) by establishing fake AI-themed websites to disseminate malware and steal personal data. The operation, uncovered by Google’s Mandiant Threat Intelligence team, has been ongoing since mid-2024 and is linked to a threat group with connections to Vietnam, identified as UNC6032.

How the scam works

According to Google, the attackers promote these fake AI tools through ads on social media platforms such as Facebook and LinkedIn. These ads mimic legitimate AI services like Luma AI, Canva’s Dream Lab, and Kling AI to trick users into visiting fraudulent websites. Once users land on these pages, they are shown an interface that claims to offer AI-generated videos or images.

Regardless of the input provided, the websites always serve a ZIP file for download. This archive contains an executable disguised with a double extension — for example, .mp4.exe — and uses common media icons to avoid raising suspicion. When launched, this file installs malware on the victim’s system.

What the malware does

Google’s researchers explain that the initial malware, named STARKVEIL, is a Rust-based dropper. It unpacks additional components designed to harvest data such as login credentials, credit card information, and cookies. In many cases, this data is exfiltrated via the Telegram API to remote servers.

The campaign also deploys other malware families, including GRIMPULL, XWORM, and FROSTRIFT, each with its own purpose — from keylogging and USB spreading to encrypted communication with command-and-control servers and gathering system details. These malware strains are built to avoid detection through sandbox and virtual machine checks.

Scale and spread

Google’s report reveals that over 30 fake domains have been created since mid-2024. A sample of 120 Facebook ads tied to this campaign reached an estimated 2.3 million users in EU countries. Similar ads on LinkedIn reportedly received between 50,000 to 250,000 impressions, primarily targeting users in the US, Europe, and Australia.

Meta has been working with Google to remove the fraudulent content and disable accounts linked to the operation.

Stay alert

With AI tools gaining popularity, Google warns users to be cautious when engaging with new services online. It is important to verify website authenticity and avoid downloading files from unfamiliar or untrusted sources. Updated antivirus software and browser protections can also help guard against such threats.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

MC Tech Desk Read the latest and trending tech news—stay updated on AI, gadgets, cybersecurity, software updates, smartphones, blockchain, space tech, and the future of innovation.
first published: Jun 1, 2025 08:18 am

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347