logo

Cybercriminals exploit AI hype to spread ransomware, malware

ID: 2aa51984-6948-5aa2-9366-e7fff9f2285c

STIX ID: report--2aa51984-6948-5aa2-9366-e7fff9f2285c

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-05-29

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Threat actors are luring victims with fake AI tool websites and malvertising to distribute malicious payloads: CyberLock (PowerShell ransomware) encrypts files and demands Monero ransom; Lucky_Gh0$t (derived from Yashma/Chaos) is packaged as a fake ChatGPT installer and encrypts or destroys files; and Numero corrupts the Windows UI in an infinite loop rendering systems unusable. These campaigns use SEO poisoning, legitimate open-source binaries to evade detection, and social-engineering promises (e.g., free subscriptions) to coax victims into executing droppers and loaders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.