HomeSecurityHackers exploit AI to spread ransomware

Hackers are exploiting AI to spread ransomware

Hackers associated with lesser-known ransomware and malware projects are now using Artificial Intelligence (AI) tools as bait to infect unsuspecting victims with malicious content.

See also: Interlock ransomware: Gang uses new NodeSnake RAT

ransomware AI

This development follows a trend that has been growing since last year, when advanced malicious actors began using deepfake content creators to spread malware. This type of bait has been widely adopted by groups operating info-stealer malware and ransomware operations aimed at infiltrating corporate networks.

Cisco Talos researchers have identified the same technique being used by smaller ransomware groups such as CyberLock, Lucky_Gh0$t , and a new malware called Numero. The malicious payloads are promoted through SEO poisoning and malvertising techniques, with the aim of appearing high in search results for specific terms.

CyberLock is PowerShell -based ransomware , distributed via a fake AI tool website (novaleadsai[.]com), which pretends to be the genuine novaleads.app website. Victims are lured in by the offer of a free 12-month subscription to the AI ​​tool, leading them to download a .NET loader that installs the ransomware.

Once executed on the victim's system, CyberLock encrypts files on multiple disk partitions, appending the .cyberlock to the locked files. The ransom note demands a payment of $50,000 in the Monero, claiming that the money will be used for "humanitarian purposes" in Palestine, Ukraine, Africa, and Asia.

See also: DragonForce ransomware abuses SimpleHelp

Lucky_Gh0 $t is a new ransomware strain derived from Yashma, which in turn is based on Chaos ransomware.

Hackers are exploiting AI to spread ransomware

Cisco analysts observed its distribution via a fake ChatGPT installer, named “ChatGPT 4.0 full version – Premium.exe”, packaged in a self-extracting archive. The package includes genuine Microsoft open-source AI tools, along with the ransomware payload, likely to evade detection by antivirus programs.

If executed, the malware encrypts files smaller than 1.2GB , adding random four-digit extensions. Larger files are overwritten with useless data of the same size and deleted. Lucky_Gh0$t victims receive a personal identifier (ID) and instructions to contact the attacker via the secure messaging platform Session for ransom negotiations and decryption.

Finally, a new malware called Numero appears as an installer for InVideo AI, but is actually designed to target Windows.

The software is distributed via a dropper that includes a batch file, a VB script , and an executable file named wintitle.exe. When executed, it operates in an infinite loop, causing continuous alteration to the user's graphical environment, replacing window titles, buttons, and content with the numeric sequence “1234567890”.

See also: Iranian man confesses to involvement in Robbinhood ransomware

Based on the above, it is clear that cyberattacks are evolving rapidly, with perpetrators exploiting the growing popularity of AI technology as a means of spreading ransomware. Now, these are not just mass attacks, but targeted campaigns that combine social engineering, fake AI tools, and evasion techniques, such as using real Microsoft files or distributing via SEO poisoning. This new generation of malware suggests that organizations and users should be especially wary of “free” or “premium” AI applications that are distributed through unofficial channels. Prevention and awareness are more critical than ever.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS