logo

Beware: Weaponized AI Tool Installers Threaten Devices with Ransomware Infection

ID: e618505e-045b-538a-9fe0-54f346026f9e

STIX ID: report--e618505e-045b-538a-9fe0-54f346026f9e

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2025-05-30

Date Updated: 2026-04-19

Author: Mandvi

...
...

Cisco Talos identified a campaign where threat actors distribute malware under the guise of legitimate AI tool installers: CyberLock (PowerShell/.NET ransomware that encrypts files, appends ".cyberlock", attempts anti-forensics, and demands Monero), Lucky_Gh0$t (evolution of Yashma/Chaos that encrypts or destructs files depending on size), and Numero (destructive malware that corrupts the Windows GUI and system components). Distribution leverages fake sites impersonating AI vendors, SEO poisoning, and messaging platforms; the report details technical behaviors, ransom tactics, and recommends source verification, endpoint defenses, backups, and user awareness to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.