AI Lures Turn Dangerous: SEO Poisoning Campaigns Spread Infostealers via ChatGPT and Luma AI Searches

Listen to this Post

Featured Image

Introduction: When Curiosity Meets Cybercrime

As interest in artificial intelligence explodes, so too does cybercriminal activity exploiting that curiosity. AI tools like ChatGPT and Luma AI have become household names, often searched on Google by millions of users eager to experiment with new technology. But now, that very enthusiasm is being weaponized. A new and sophisticated form of attack—SEO poisoning—is targeting unsuspecting users by mimicking official-looking AI tool websites, infecting them with data-stealing malware under the guise of helpful AI resources.

This article uncovers a recent and growing cybersecurity threat where malicious actors use AI-related keywords to manipulate search engines and distribute malware. The campaign doesn’t just reflect a clever trick—it showcases the new face of cybercrime in the AI age, where the border between legitimate tech discovery and digital compromise is thinner than ever.

the Original

Researchers at Zscaler ThreatLabz have uncovered an SEO poisoning campaign that leverages the popularity of AI tools like ChatGPT and Luma AI to spread infostealing malware. These malicious actors are creating fake websites using platforms like WordPress, optimized to rank highly on Google. Once users click on these links, they are redirected through layers of obfuscated JavaScript leading to malware installations, notably Vidar, Lumma, and Legion Loader.

The attack process begins when a user visits a site pretending to offer AI content. JavaScript on the page collects browser data, encrypts it using XOR, and sends it to a command-and-control server. Based on the response, users are redirected again—often to a payload-hosting page that automatically initiates downloads of malware. These payloads arrive as password-protected ZIP files containing a massive NSIS installer (\~800MB) designed to evade detection. Once run, the files reconstruct and execute malicious scripts using AutoIT, ultimately deploying the malware.

The malware types involved are designed to steal sensitive data such as browser credentials, system configurations, and even cryptocurrency wallets via browser extensions. Notably, the malware is hosted via AWS CloudFront, giving it the appearance of legitimacy and helping it avoid traditional security filters.

The

The article urges vigilance and recommends that cybersecurity teams proactively identify and block indicators of compromise (IoCs) associated with Lumma, Vidar, and Legion Loader. Zscaler’s cloud sandbox platform includes technical indicators and detection details that organizations can use to protect their users and systems.

What Undercode Say:

This campaign is a textbook case of cybercriminals capitalizing on hype cycles. AI, particularly generative AI tools like ChatGPT, has become a magnet for public interest. Attackers are simply leveraging this attention and redirecting it—literally and figuratively—toward malware distribution. The strategy works because it targets the average user who isn’t hyperaware of cybersecurity threats but is eager to try the latest tech.

There are several important technical and behavioral observations to highlight:

SEO poisoning is not new, but using it with high-volume AI search terms is what gives this campaign its effectiveness. Ranking in the top 3 on Google is a potent vector for infection—users trust those top results.

Cloud services like AWS CloudFront are being abused, not compromised. This nuance makes the malware harder to detect because security tools often whitelist traffic from major CDNs. It’s social engineering paired with infrastructural camouflage.

Payload packaging is smart. An 800MB installer not only overwhelms many sandbox environments but also seems like a legitimate software download to users. The use of password-protected ZIP files adds another layer of obfuscation to evade scanning engines.

Multistage redirects and IP filtering demonstrate how targeted these campaigns are. They’re not just hoping to hit anyone—they’re filtering victims to optimize for environments where they can thrive undetected.

The ultimate goal isn’t just stealing credentials—cryptocurrency theft is a major endgame. Browser extensions that access wallets are high-value targets, and once compromised, users may not even realize it until it’s too late.

AI’s reputation is being manipulated, and this has broader implications. If people begin to associate AI tools with risk due to these campaigns, it could stunt adoption or lead to overreliance on closed ecosystems where “safety” is promised at the cost of openness.

In essence, this attack is a collision between curiosity and complacency. AI draws the user in; SEO tricks convince them it’s legitimate; packaging and delivery mechanisms hide the threat until it’s too late.

Proactive Solutions for Users and Enterprises:

Always verify URLs for AI tools via official sources or reputable tech sites.
Use threat protection software that can analyze ZIP files and scan embedded scripts.
Educate end-users about the risks of downloading tools from unknown sites—even if they appear high in Google search results.
Implement web filtering policies that can block traffic to domains known for malware or high-risk behavior.
Monitor browser extensions in enterprise environments, especially those with access to financial tools or confidential platforms.

The AI revolution shouldn’t become the new playground for digital thieves. But unless awareness and technical defenses evolve quickly, that’s exactly what it risks becoming.

🔍 Fact Checker Results

✅ Vidar and Lumma Stealers: Confirmed malware used for credential theft and browser data extraction.

✅ SEO Poisoning via Google Search: Verified by Zscaler’s public threat blog and other cybersecurity experts.

✅ Use of AWS CloudFront: Misuse of CDN infrastructure for malware hosting has been documented in multiple campaigns since 2023.

📊 Prediction: The Next Phase of AI-Related Cybercrime

As AI search volume surges, cybercriminals will likely escalate these campaigns by targeting:

Voice assistants and AI agents embedded in browsers or smart devices.
Open-source AI tool repositories like Hugging Face or GitHub, where malware can be slipped into pre-trained models or libraries.
AI plugins and extensions that seem helpful but are loaded with spyware or steal user API tokens.

We anticipate that within the next 12 months, malicious AI-themed Chrome extensions will surpass fake AI download sites as the top attack vector. The mix of accessibility and user trust in browser extensions will make them ripe for exploitation.

Cybersecurity in the age of AI isn’t just about defending against rogue models—it’s about recognizing that AI’s popularity itself is now a weapon in the attacker’s toolkit.

References:

Reported By: www.darkreading.com
Extra Source Hub:
https://www.reddit.com/r/AskReddit
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin