AI brands as bait: How threat actors are using the AI hype in social engineering

June 9, 2026, 8:57 a.m.

Description

Threat actors are increasingly leveraging the global interest in artificial intelligence by impersonating popular AI platforms such as ChatGPT, Copilot, DeepSeek, and Claude in social engineering campaigns. These operations span phishing attacks, malvertising, and search engine optimization-driven tactics that ultimately lead to credential theft, financial fraud, or malware infections. Observed campaigns include ChatGPT-themed phishing collecting credit card data targeting South Africa, Claude-themed adversary-in-the-middle attacks harvesting credentials and access tokens, malvertising campaigns distributing Vidar stealer through fake AI plugin downloads, and fraudulent DeepSeek V4 installers on GitHub. The initial access broker Storm-3075 has been identified employing AI-themed malvertising, while the financially motivated actor Fox Tempest provides malware-signing-as-a-service to enhance payload legitimacy. These campaigns combine traditional social engineering tactics with AI branding to improve success...

Date

  • Created: June 8, 2026, 7:36 p.m.
  • Published: June 8, 2026, 7:36 p.m.
  • Modified: June 9, 2026, 8:57 a.m.

Indicators

  • 791efb555eefb7215e96659a1353a97416743b66bdd72705493129c64057d40e
  • 5455341ed1bbe75a664fca2dd0794c508e1874f75360253a7ff5bc119bc92d80
  • 0a26238f6c516de5885457c93042531aa59bc206a9537cebf5267cedc6c68531
  • 25270cc429ada8028b5b33220ed412c47907ecceea7377d608fac5af01bed56a
  • 8610d4fb0ec5b525071c2aaec4df0f8fcbb3673aba58a7e1959fc44e83c0e2ca
  • 56d722b0331bf0aaa86bb37483486c6dff6ad9427fc473ed7c3226c21a9bdd23
  • 99231deb373997364381d1eb513d2d42231d418c3a2db9007c5af9bd56ab9371
  • c7c5072df9f83f4c440a5c3bb4be1d5f6c67bbf78f196406ca20d27b43b975b8
  • http://dash.awaydouble.org/0v2auth

Attack Patterns

Additional Informations

  • Finance
  • Education
  • Retail
  • Technology
  • brokeapt.com
  • servicing.pureplantcravings.com
  • legendarytrendsbay.shop
  • grupoconstat.bitrix24.com.br
  • pan.rongtv.xyz
  • pan.ssffaa19.xyz
  • dash.awaydouble.org