Cyber attackers are exploiting Google search results related to popular AI platforms like ChatGPT and Luma AI to distribute malware through sophisticated black hat SEO campaigns. These campaigns use fake AI websites, browser fingerprinting, and obfuscated payloads containing info-stealers such as Vidar, Lumma, and Legion Loader, leveraging legitimate infrastructure to evade detection. #Vidar #Lumma #LegionLoader #AIThreats #BlackHatSEO
Keypoints
- Threat actors create SEO-optimized fake AI websites to hijack search traffic and distribute malware.
- Malicious sites deploy scripts that fingerprint browsers and redirect users to payloads hosted on trusted infrastructure like AWS CloudFront.
- Payloads include large installers for infostealers Vidar and Lumma, and malicious Legion Loader modules, designed to evade sandbox detection.
- The campaign leverages AI-related keywords for scale, exploiting curiosity around generative models to spread malware.
- Users should be cautious when downloading AI tools from third-party sites and defenders should monitor traffic to malicious domains like gettrunkhomuto[.]info.
Read More: https://thecyberexpress.com/poisoning-google-search-results-infostealers/