Cybercriminals exploit AI hype to spread ransomware, malware
ID: 2aa51984-6948-5aa2-9366-e7fff9f2285c
STIX ID: report--2aa51984-6948-5aa2-9366-e7fff9f2285c
Feed Name: Bleeping Computer
Threat actors are luring victims with fake AI tool websites and malvertising to distribute malicious payloads: CyberLock (PowerShell ransomware) encrypts files and demands Monero ransom; Lucky_Gh0$t (derived from Yashma/Chaos) is packaged as a fake ChatGPT installer and encrypts or destroys files; and Numero corrupts the Windows UI in an infinite loop rendering systems unusable. These campaigns use SEO poisoning, legitimate open-source binaries to evade detection, and social-engineering promises (e.g., free subscriptions) to coax victims into executing droppers and loaders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
