AI brands as bait: How threat actors are using the AI hype in social engineering
Threat actors are increasingly leveraging the global interest in artificial intelligence by impersonating popular AI platforms such as ChatGPT, Copilot, DeepSeek, and Claude in social engineering campaigns. These operations span phishing attacks, malvertising, and search engine optimization-driven tactics that ultimately lead to credential theft, financial fraud, or malware infections. Observed campaigns include ChatGPT-themed phishing collecting credit card data targeting South Africa, Claude-themed adversary-in-the-middle attacks harvesting credentials and access tokens, malvertising campaigns distributing Vidar stealer through fake AI plugin downloads, and fraudulent DeepSeek V4 installers on GitHub. The initial access broker Storm-3075 has been identified employing AI-themed malvertising, while the financially motivated actor Fox Tempest provides malware-signing-as-a-service to enhance payload legitimacy. These campaigns combine traditional social engineering tactics with AI branding to improve success...
Pulse ID: 6a2719a4165e6fddbfbf8f91
Pulse Link: https://otx.alienvault.com/pulse/6a2719a4165e6fddbfbf8f91
Pulse Author: AlienVault
Created: 2026-06-08 19:36:04
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #Africa #ChatGPT #CreditCard #CyberSecurity #FinancialFraud #GitHub #ICS #InfoSec #Mac #Malvertising #Malware #OTX #OpenThreatExchange #Phishing #RAT #SocialEngineering #Vidar #bot #AlienVault