AI Deception Alert: How Cybercriminals Are Weaponizing Fake AI Tools to Spread Ransomware


# Cybercriminals Leverage Fake AI Tools to Distribute Ransomware

Threat actors are increasingly using artificial intelligence tools as lures to distribute malicious payloads, according to recent findings from Cisco Talos researchers. This trend, which began with advanced threat actors using deepfake generators, has now spread to smaller ransomware operations and malware distributors.

## New Threats Identified

Three notable threats have emerged in this space:

### CyberLock Ransomware
This PowerShell-based ransomware is distributed through a fake AI website (novaleadsai[.]com) that impersonates the legitimate novaleads.app. Victims are enticed with offers of free 12-month subscriptions, leading them to download a .NET loader that deploys the ransomware. Once executed, CyberLock encrypts files across multiple disk partitions and appends the .cyberlock extension to locked files. The attackers demand $50,000 in Monero cryptocurrency, claiming the funds will support humanitarian causes.

### Lucky_Gh0$t Ransomware
This new strain, derived from Yashma (itself based on Chaos ransomware), is distributed as a fake “ChatGPT 4.0 full version – Premium.exe” installer. The package cleverly includes legitimate Microsoft open-source AI tools alongside the malicious payload to evade detection. Upon execution, it encrypts files smaller than 1.2GB with random four-character extensions, while larger files are replaced with junk data and deleted. Victims receive a personal ID and must contact attackers through the Session messaging platform.

### Numero Malware
This new malware masquerades as an InVideo AI installer but is designed to render Windows systems unusable. Delivered via a dropper containing batch files, VB scripts, and an executable, Numero runs in an infinite loop that corrupts the graphical user interface by overwriting window titles, buttons, and content with the numeric string “1234567890.” While it doesn’t encrypt or destroy data, it effectively locks systems in a visually corrupted state.

## Protection Recommendations

As cybercriminals capitalize on growing interest in AI tools, users should exercise caution when downloading files from unfamiliar websites. Security experts recommend:

– Sticking to major, established AI projects
– Downloading installers only from official websites
– Avoiding links from promoted search results or social media posts

This evolving threat landscape highlights how quickly cybercriminals adapt to exploit new technological trends and user interests.

Share This Article