Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Tedhar CEO Paolo Ardoino says ‘No need is needed’

    June 8, 2025

    What is MicroSD Express? Everything You Need To Know

    June 8, 2025

    5 to avoid pressure washing mistakes

    June 8, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Cyber ​​Criminals ransomware exploits AI promotion to spread malware
    Security

    Cyber ​​Criminals ransomware exploits AI promotion to spread malware

    PineapplesUpdateBy PineapplesUpdateMay 31, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Cyber ​​Criminals ransomware exploits AI promotion to spread malware
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cyber ​​Criminals ransomware exploits AI promotion to spread malware

    Actor with danger associated with low-knowledge ransomware and malware projects now now use AI tools to infect victims with malicious payloads.

    This development follows a trend that has been growing since last year, begins with advanced danger actors using deepfec content generators to infect victims with malware.

    They have become lures widely adopted Attempts to dissolve the corporate network by information-information malware operators and ransomware operations.

    Cisco Talos Researcher Found out After the same technique, small ransomware teams are now known as cyberlock, lucky_GH 0 $ T, and a new malware called Numero.

    The malicious payload is promoted via SEO poisoning and the search engine results for specific terms are malwarting to rank high in the results.

    AI Equipment Immunity

    Cyberlock is the powerrashel-based ransomware given through a fake AI tool website (Novaleadsai (.) Com), which presents as valid novaleads.app.

    Malicious website
    Mulnerable website provides cyberlock ransomware
    Source: Cisco Talos

    The victims are lured by a free 12 -month membership proposals, leading them to download a .NET loader that deploys the ransomware.

    Once the victim is executed on the machine, the cyberlock encrypted files in several disk division, which adds. Cyberlock Extension on locks.

    The Ransum Note Hard-to-Treas Monero demands a ransom of $ 50,000 in cryptocurrency, claiming that money would support human causes in Palestine, Ukraine, Africa and Asia.

    Wallpaper used by cyberlock
    Pentinellabs blog used as wallpaper by Cyberlock
    Source: Cisco Talos

    Lucky_gh0 $ T is a new ransomware strain taken from Yashma, which is based on the chaos ransomware itself.

    Cisco analysts noticed that it is being distributed as a fake chatgpt installer (“” Chatgpt 4.0 Full Version – Premibum.exe “) is packed in a self -evidence collection.

    The package includes a valid microsoft open-source AI tools with ransomware payload, which is likely to detect antivirus.

    If executed, it encryps the files smaller than 1.2GB, which combines random four-ornament extensions, while large files are replaced and removed with the same size junk file.

    Victims of Lucky_gh0 $ T receive an individual ID and are instructed to contact the attacker through a safe messenger platform session safe for ransom talks and decryption.

    Lucky_gh0 $ t ransom note
    Lucky_gh0 $ t ransom note
    Source: Cisco Talos

    Finally, a new malware, as an invoideo AI installer, is called Numero Muscanders, but is designed to attack the Windows system.

    Malware is an executable in a dropper called a batch file, VB script, and an executable wintitle.exe.

    It executes an infinite loop, constantly corrupted the victim’s graphical user interface by the content, button, and numeric string “by the material with 1234567890.

    Windows dialog after a numero infection
    Windows dialog after a numero infection
    Source: Cisco Talos

    Although no data is destroyed or encrypted by the nambbo, the malware presents the Windows system that makes it completely unusable. At the same time, the infinite loop that runs ensures that the system is “lock” in this blind corrupt state.

    Since more cyber criminals try to take advantage of people’s increasing interest in AI Tools, it is advisable to take precautions with files downloaded from suspected websites.

    It would be more prudent to stick to major AI projects instead of using new tools and sources instead of following the link from promoted results or social media posts.


    Red Report 2025

    Based on the analysis of 14M malicious tasks, search for the top 10 MITERAT & CK techniques behind the 93% attacks and how to defend them against them.

    criminals Cyber exploits Malware promotion Ransomware spread
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThis cool 2 -in -1 USB cable is very good, and it is less than $ 20
    Next Article How to see ‘Beckham and Friends Live’ Online-Stream UCL Final Watch with David Beckham, Tom Cruz and Odel Beckham Junior.
    PineapplesUpdate
    • Website

    Related Posts

    Security

    Remove project directors presented as malicious NPM package utilities

    June 8, 2025
    Security

    Supply series attacks Glustac NPM package with 960K weekly download

    June 7, 2025
    Gadgets

    Cyber ​​criminals love this ancient Windows tool, but a small CLI utility is their new secret weapon

    June 7, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025594 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025536 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025465 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Meta delay entrusts ‘Bhamoth’ AI model, Openi and Google more than one more head start

    May 16, 20250 Views

    The OURA ring found a new rival with just one titanium design and 24/7 biometric tracking – no membership is required

    May 16, 20250 Views

    Filecoin, Lockheed Martin Test IPFS in space

    May 16, 20250 Views
    Our Picks

    Tedhar CEO Paolo Ardoino says ‘No need is needed’

    June 8, 2025

    What is MicroSD Express? Everything You Need To Know

    June 8, 2025

    5 to avoid pressure washing mistakes

    June 8, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.