Cybercriminals are targeting users through counterfeit Facebook pages and sponsored advertisements that impersonate Kling AI, a popular AI image and video generation platform. These deceptive campaigns lead victims to malicious websites where they unknowingly download harmful malware.
## The Attack Strategy
According to Check Point researchers, the campaign first detected in early 2025 uses fake Facebook pages to distribute remote access trojans (RATs) that grant attackers control over victims’ systems. Users are directed to spoofed websites like klingaimedia[.]com or klingaistudio[.]com, which promise AI-generated content but instead deliver malicious Windows executables disguised with double extensions and special characters.
The malware operates in two stages:
– An initial loader that monitors for security analysis tools and establishes persistence
– A second-stage PureHVNC RAT that injects itself into legitimate Windows processes like CasPol.exe or InstallUtil.exe
## Data Theft Capabilities
The sophisticated malware can:
– Steal browser-stored credentials and session tokens
– Extract data from cryptocurrency wallet extensions
– Capture screenshots when banking or wallet applications are opened
– Exfiltrate sensitive information to command-and-control servers
## Attribution and Broader Context
Check Point identified at least 70 promoted posts from fake Kling AI social media pages. Evidence suggests Vietnamese threat actors may be behind the campaign, consistent with their history of using Facebook malvertising to distribute stealer malware and exploiting the popularity of generative AI tools.
This campaign is part of a larger trend of social media scams. The Wall Street Journal reports that Meta is struggling with an “epidemic of scams” across Facebook and Instagram, with many originating from China, Sri Lanka, Vietnam, and the Philippines. Rest of World also notes that fake job ads on social platforms are increasingly used to traffic individuals into scam operations throughout Southeast Asia.
