Close Menu
DISADISA
  • Home
  • News
  • Social Media
  • Disinformation
  • Fake Information
  • Social Media Impact
Trending Now

OpenAI Identifies Disinformation Operation Exploiting ChatGPT

August 26, 2026

Addressing Medical Misinformation: A Formal Discussion

August 26, 2026

Here are several formal options for the title, ranging from a direct translation to slightly more editorialized versions.

Option 1: Direct & Formal This version uses a direct translation with formal wording.

Artificial Intelligence Lowers the Barriers to Chinese Information Warfare Against Japan

Option 2: Emphasizing Causality This version uses a colon to clearly link the cause and effect.

Artificial Intelligence and the Lowering of Barriers: China’s Information Warfare Against Japan

Option 3: Descriptive & Impact-Focused This version emphasizes the outcome and impact of the technology.

The Role of AI in Facilitating China’s Information Warfare Capacity Against Japan

Option 4: Stronger Stance This version uses stronger verbs like “Democratizing” which implies widespread access.

How AI is Democratizing China’s Information Warfare Capabilities Against Japan

Option 5: Academic & Neutral This version uses a noun-heavy structure, common in academic writing.

The Impact of Artificial Intelligence on the Barriers to Chinese Information Warfare Against Japan

August 26, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
DISADISA
Newsletter
  • Home
  • News
  • Social Media
  • Disinformation
  • Fake Information
  • Social Media Impact
DISADISA
Home»Fake Information»Malicious Social Media Campaign Promotes Fraudulent AI Editor Website for Credential Theft
Fake Information

Malicious Social Media Campaign Promotes Fraudulent AI Editor Website for Credential Theft

Press RoomBy Press RoomDecember 22, 2024No Comments
Facebook Twitter Pinterest LinkedIn Tumblr Email

Social Media Hijackings Fuel AI Photo Editor Scam: Threat Actors Steal Credentials and Deploy Malware

A sophisticated malvertising campaign is exploiting the growing popularity of AI photo editing tools to steal credentials and distribute malware.  Threat actors are hijacking social media pages, primarily those related to photography, renaming them to mimic legitimate AI photo editor brands, and then using paid advertisements to boost malicious posts containing links to fake websites. These websites, designed to mirror the authentic platforms, trick unsuspecting users into downloading what they believe is a photo editor but is, in fact, an endpoint management utility that grants the attackers remote control of their devices.

The attack begins with the compromise of social media accounts, typically achieved through phishing. Threat actors send spam messages containing malicious links, often disguised as personalized link pages or utilizing Facebook’s open redirect URL to appear legitimate. These links lead to fraudulent account protection pages that prompt users to enter their login credentials, including phone numbers, email addresses, birthdays, and passwords.  Once the attackers gain access to the account, they quickly change the page name to resemble a popular AI photo editor, like Evoto in the observed cases, and begin posting malicious advertisements.

These ads, promoting the fake AI photo editor, redirect users to convincingly designed websites that closely mimic the legitimate photo editor’s site. This deceptive tactic effectively lures victims into downloading the malicious installer package. The package itself is a legitimate endpoint management utility, ITarian, configured maliciously by the attackers. This clever use of a legitimate tool allows the attackers to bypass initial security scans, as the installer file does not contain inherently malicious components. Instead, the malicious configuration is retrieved upon execution, further obscuring the attack.

Upon installation, the ITarian software enables the attackers to remotely control the victim’s device. They then deploy scheduled tasks that download and execute additional payloads, primarily the Lumma Stealer malware.  This stealer is designed to exfiltrate a wide range of sensitive data, including cryptocurrency wallet files, browser data, password manager databases, and other valuable information.  The attackers also deploy a script that disables Microsoft Defender’s scanning capabilities on the C: drive, further compromising the victim’s security and enabling persistence.

The Lumma Stealer operation is characterized by specific communication patterns with its command-and-control server. This involves two consecutive POST requests, the second of which returns a Base64 encoded configuration file. This configuration file, once decrypted, reveals the stealer’s comprehensive list of targeted data. The attack’s scale is significant, with download statistics embedded within the malicious JavaScript revealing thousands of downloads across both Windows and macOS platforms, although the macOS version currently appears to be a harmless redirect to apple.com.

This sophisticated campaign underscores the increasing threat posed by social media-based attacks and the ingenuity of cybercriminals in exploiting trending technologies like AI.  To protect themselves, users are strongly advised to enable multi-factor authentication (MFA) on all social media accounts and employ strong, unique passwords. Regularly updating software and exercising caution when clicking on links, especially those requesting personal information or login credentials, are crucial. Monitoring social media accounts for unusual activity, such as unexpected login attempts or changes to account information, can also help detect potential compromises.

For organizations, educating employees about phishing tactics and investing in robust security solutions is essential. Endpoint protection platforms that offer multi-layered defense and behavior detection capabilities can help identify and block malicious tools like ITarian before they can inflict damage.  In the context of the broader threat landscape surrounding AI, tools like deepfake detectors can provide added protection against AI-powered scams during video calls, further bolstering security against the evolving tactics employed by cybercriminals. The ongoing abuse of legitimate tools and platforms highlights the need for constant vigilance and proactive security measures. By understanding the techniques used in these attacks, both individuals and organizations can better protect themselves from falling victim to these increasingly sophisticated schemes.

Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email

Read More

Tate Brothers Acknowledge Their Ostentatious Displays of Wealth Are Fabricated

August 25, 2026

Formal Advisory Warns Social Media Users of Fraudulent Protection Services

August 25, 2026

Identifying the Most Common Scams Originating on Social Media

August 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Our Picks

Addressing Medical Misinformation: A Formal Discussion

August 26, 2026

Here are several formal options for the title, ranging from a direct translation to slightly more editorialized versions.

Option 1: Direct & Formal This version uses a direct translation with formal wording.

Artificial Intelligence Lowers the Barriers to Chinese Information Warfare Against Japan

Option 2: Emphasizing Causality This version uses a colon to clearly link the cause and effect.

Artificial Intelligence and the Lowering of Barriers: China’s Information Warfare Against Japan

Option 3: Descriptive & Impact-Focused This version emphasizes the outcome and impact of the technology.

The Role of AI in Facilitating China’s Information Warfare Capacity Against Japan

Option 4: Stronger Stance This version uses stronger verbs like “Democratizing” which implies widespread access.

How AI is Democratizing China’s Information Warfare Capabilities Against Japan

Option 5: Academic & Neutral This version uses a noun-heavy structure, common in academic writing.

The Impact of Artificial Intelligence on the Barriers to Chinese Information Warfare Against Japan

August 26, 2026

Meta, Parent of Facebook, Reaches Nearly $18 Billion Settlement in Youth Mental Health Case

August 26, 2026

The Failure of Ukrainian Statehood Thirty-Five Years After Independence

August 26, 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo

Don't Miss

Social Media Impact

U.S. Trial of Meta Examines Social Media’s Impact on Minors.

By Press RoomAugust 26, 20260

Meta Lawsuit Heats Up: 29 States Accuse Tech Giant of Endangering Children In a landmark…

OpenAI Terminates Russian Accounts Employed in Influence Operations.

August 26, 2026

Early Social Media Use Linked to Lower Math and Language Scores in 5,227 Children, Study Identifies Mitigating Factor

August 26, 2026

OpenAI Suspends ChatGPT Accounts Linked to Russian Disinformation Operations

August 26, 2026
DISA
Facebook X (Twitter) Instagram Pinterest
  • Home
  • Privacy Policy
  • Terms of use
  • Contact
© 2026 DISA. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.