logo

Cybercriminals camouflaging threats as AI tool installers

ID: c5fcfdb6-399c-53ab-aa6a-d59da738275d

STIX ID: report--c5fcfdb6-399c-53ab-aa6a-d59da738275d

Feed Name: Cisco Talos

Threat Score
75/100

Date Published: 2025-05-29

Date Updated: 2026-04-27

Author: Chetan Raghuprasad

...
...

Cisco Talos reports active malicious campaigns distributing malware masquerading as legitimate AI tool installers: CyberLock (PowerShell-based ransomware that encrypts many file types, sets ransom notes and wipes free space), Lucky_Gh0$t (a Yashma/Chaos ransomware variant delivered via SFX installer with destructive behavior for large files), and Numero (a window-manipulating destructive binary). The report describes distribution vectors (SEO-poisoning, fake sites, Telegram/messaging), technical analysis of malware behaviors, ransom demands and notes, detection/mitigation guidance, ClamAV and Snort detections, and links to IOCs on GitHub.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.