Fake AI editor ads on Facebook push password-stealing malware

Share:

​A Facebook malvertising campaign targets users searching for AI image editing tools and steals their credentials by tricking them into installing fake apps that mimic legitimate software.

The attackers exploit the popularity of AI-driven image-generation tools by creating malicious websites that closely resemble legitimate services and trick potential victims into infecting themselves with information stealer malware, as Trend Micro researchers who analyzed the campaign found.

The attacks start with phishing messages sent to Facebook page owners or administrators, which will send them to fake account protection pages designed to trick them into providing their login information.

After stealing their credentials, the threat actors hijack their accounts, take control of their pages, publish malicious social media posts, and promote them via paid advertising.

“We discovered a malvertising campaign involving a threat actor that steals social media pages (typically related to photography), changing their names to make them seem connected to popular AI photo editors,” said Trend Micro threat researcher Jaromir Horejsi.

“The threat actor then creates malicious posts with links to fake websites made to resemble the actual website of the legitimate photo editor. To increase traffic, the perpetrator then boosts the malicious posts via paid ads.”

​Facebook users who click the URL promoted in the malicious ad are sent to a fake web page impersonating legitimate AI photo editing and generating software, where they are prompted to download and install a software package.

However, instead of AI image editing software, the victims install the legitimate ITarian remote desktop tool configured to launch a downloader that automatically deploys the Lumma Stealer malware.

The malware then quietly infiltrates their system, allowing the attackers to collect and exfiltrate sensitive information like credentials, cryptocurrency wallet files, browser data, and password manager databases.

This data is later sold to other cybercriminals or used by the attackers to compromise the victims’ online accounts, steal their money, and promote further scams.

“Users should enable multi-factor authentication (MFA) on all social media accounts to add an extra layer of protection against unauthorized access,” Horejsi advised.

“Organizations should educate their employees on the dangers of phishing attacks and how to recognize suspicious messages and links. Users should always verify the legitimacy of links, especially those asking for personal information or login credentials.”

In April, a similar Facebook malvertising campaign promoted a malicious page impersonating Midjourney to target almost 1.2 million users with the Rilide Stealer Chrome browser extension.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
12:32 am, Jun 21, 2025
weather icon 19°C
L: 17° | H: 20°
clear sky
Humidity: 72 %
Pressure: 1021 mb
Wind: 9 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 5%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
17° | 20°°C 0.25 mm 25% 9 mph 72 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
17° | 26°°C 1 mm 100% 16 mph 88 % 1014 mb 0 mm/h
Mon Jun 23 10:00 pm
weather icon
15° | 24°°C 0.2 mm 20% 14 mph 77 % 1017 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
14° | 25°°C 0 mm 0% 12 mph 76 % 1017 mb 0 mm/h
Wed Jun 25 10:00 pm
weather icon
17° | 20°°C 1 mm 100% 11 mph 82 % 1011 mb 0 mm/h
Today 1:00 am
weather icon
18° | 19°°C 0 mm 0% 5 mph 72 % 1020 mb 0 mm/h
Today 4:00 am
weather icon
17° | 18°°C 0 mm 0% 5 mph 68 % 1020 mb 0 mm/h
Today 7:00 am
weather icon
20° | 20°°C 0 mm 0% 6 mph 56 % 1019 mb 0 mm/h
Today 10:00 am
weather icon
27° | 27°°C 0 mm 0% 8 mph 34 % 1018 mb 0 mm/h
Today 1:00 pm
weather icon
30° | 30°°C 0 mm 0% 9 mph 25 % 1017 mb 0 mm/h
Today 4:00 pm
weather icon
33° | 33°°C 0 mm 0% 8 mph 25 % 1016 mb 0 mm/h
Today 7:00 pm
weather icon
30° | 30°°C 0 mm 0% 8 mph 28 % 1014 mb 0 mm/h
Today 10:00 pm
weather icon
25° | 25°°C 0.25 mm 25% 6 mph 42 % 1014 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€89,531.59
-1.46%
Ethereum(ETH)
€2,080.97
-4.99%
Tether(USDT)
€0.87
-0.01%
XRP(XRP)
€1.83
-2.25%
Solana(SOL)
€120.86
-5.24%
USDC(USDC)
€0.87
-0.01%
Dogecoin(DOGE)
€0.140418
-5.32%
Shiba Inu(SHIB)
€0.000010
-2.68%
Pepe(PEPE)
€0.000009
-4.70%
Peanut the Squirrel(PNUT)
€0.218243
13.10%
Scroll to Top