EXECUTIVE SUMMARY:
A malware campaign has emerged, exploiting public interest in popular AI platforms to deceive users into installing harmful software. Attackers are using search engine advertisements and phishing websites that closely mimic legitimate AI tool platforms. These deceptive pages present polished interfaces complete with fake security features like CAPTCHA prompts, luring users into downloading what appears to be a valid application. However, the installer delivered from these sites is a trojan that silently infects the system. By disguising itself as an installer for well-known AI frameworks, the malware tricks users into believing they are launching a trusted application. The fraudulent setup process hides malicious payloads that are deployed in the background, while the user sees what appears to be a standard installation process. Language markers in the code suggest the attackers may belong to a specific linguistic group, but their identities remain speculative.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A malware campaign has emerged, exploiting public interest in popular AI platforms to deceive users into installing harmful software. Attackers are using search engine advertisements and phishing websites that closely mimic legitimate AI tool platforms. These deceptive pages present polished interfaces complete with fake security features like CAPTCHA prompts, luring users into downloading what appears to be a valid application. However, the installer delivered from these sites is a trojan that silently infects the system. By disguising itself as an installer for well-known AI frameworks, the malware tricks users into believing they are launching a trusted application. The fraudulent setup process hides malicious payloads that are deployed in the background, while the user sees what appears to be a standard installation process. Language markers in the code suggest the attackers may belong to a specific linguistic group, but their identities remain speculative.[emaillocker id="1283"]
The fake installer is designed to execute a multi-step infection chain while concealing its true purpose. Upon launch, it shows a bogus CAPTCHA interface to simulate legitimacy before prompting users to choose between installing popular AI clients. Regardless of the selection, a background script begins executing PowerShell commands that weaken local security settings by excluding user directories from active scanning. The installer then initiates a domain generation routine to contact command-and-control infrastructure, retrieving an additional payload saved in a music directory. This executable is set to retry downloads millions of times, ensuring persistence. Once the secondary payload is in place, it decrypts and injects a third-stage module directly into memory—avoiding disk writes and evading many detection methods. This final stage, known as BrowserVenom, is a proxy hijacker that intercepts browser traffic. It modifies settings across Chromium and Gecko-based browsers, including installing a custom root certificate and injecting proxy configurations. As a result, all browser sessions are invisibly routed through a hardcoded remote proxy, granting the attacker access to all web communications, including sensitive data.
This malware campaign exemplifies how attackers exploit emerging technologies and public excitement to execute advanced threat operations. By crafting installers that imitate trusted AI tools, they lower the user's defenses and introduce stealthy infections with little to no warning. The final payload establishes a powerful form of control by intercepting and redirecting browser traffic through an external proxy server, enabling deep visibility into online activity. Its silent nature—avoiding dropped files, relying on memory injections, and modifying shortcuts and certificates—makes it especially hard to detect and remediate. Infections have been observed across multiple geographic regions, highlighting the global reach of this threat. The campaign serves as a reminder of the risks of downloading software from unverified sources, particularly when driven by trends or search engine results. Users are encouraged to favor official web interfaces for interacting with AI systems and to be cautious of advertisements that prompt software downloads.
THREAT PROFILE:
| Tactic | Technique ID | Technique | Sub-Technique |
| Initial Access | T1566.002 | Phishing | Spearphishing via Service |
| T1189 | Drive-by Compromise | - | |
| T1190 | Exploit Public-Facing Application | - | |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| T1037.001 | Boot or Logon Initialization Scripts | Logon Script (user-level persistence) | |
| Defense Evasion | T1562.001 | Impair Defenses | Disable or Modify Tools |
| T1027/002 | Obfuscated Files or Information | Software Packing | |
| T1140 | Deobfuscate/Decode Files or Info | - | |
| Credential Access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Collection | T1056.001 | Input Capture | Keylogging |
| T1119 | Automated Collection | - | |
| Command and Control | T1090.002 | Proxy | External Proxy |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Impact | T1496 | Resource Hijacking | - |
MBC MAPPING:
| Objective | Behaviour ID | Behaviour |
| Defense Evasion | E1112 | Modify Registry |
| Impact | B0019 | Manipulate Network Traffic |
| Collection | E1056 | Input Capture |
| Command and Control | B0030 | C2 Communication |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]