The rapid spread of artificial intelligence tools is creating new opportunities for workers and businesses, but it is also opening up another avenue for cybercriminals. Malwarebytes are warning of a network of fake websites posing as AI services, offering subscriptions for speech transcription, image creation, video editing and other functions.

These pages are designed to look like real services and use popular product names or well-known brand names, as well as services that have ceased operations. Examples identified by the researchers include GPT-6 Astra, DaVinci Resolve, PixAI, and OpenCut, as well as thenow-defunct Omegle.
Professional appearance and authentic Google login
The special element of this particular campaign is that the websites do not necessarily rely on classic phishing methods. That is, they do not necessarily display a fake form asking the user to type in their password.
Instead, they use the authentic “Sign in with Google”, which can create a strong sense of legitimacy. The user is taken to the real Google environment to sign in, and the app asks for basic information, such as name, email address, and profile photo.
The researchers note that in the cases they examined, no access to Gmail or Google Drive was requested. However, this does not mean that the service is trustworthy. On the contrary, the use of an authentic identification process can act as a "window dressing" for an otherwise deceptive service.
See also: Dubai Police: Beware of fake travel offers
Subscriptions from $10 to $2,000
After registering, visitors are asked to pay for supposed access to AI tools. The charges identified start at around $10 per month and go up to $2,000 for an annual subscription.
The financial cost, however, may be the least of the problems. Some of the platforms required users to upload documents, audio recordings, and other files in order to use the services.
This turns a seemingly simple software purchase into a potential data breach. A file uploaded to an unknown platform could contain personal information, corporate information, confidential documents, meeting recordings, or customer data.
The danger of Shadow IT in businesses
The risk for businesses is particularly significant, as an employee may decide to use an AI service without first informing the IT department.
This practice is known as shadow IT and is already a problem for organizations, even when employees are using legitimate services. In the case of a fake platform, however, the situation becomes much more dangerous, as the business may have no control over where the data is stored or who has access to it.
A marketing department, for example, might upload a presentation for automatic transcription or summarization, thinking it’s using a professional tool. If the platform is fake, the file could end up on an unknown server without the company realizing it.
See also: Beware: Open-Source Neptune Stealer Delivered via GitHub

Same infrastructure behind different AI services
Malwarebytes believes that the different websites detected are likely connected. Researchers noted common features in their construction, identical files, and associations in the email addresses used by the alleged developers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Even more interestingly, the websites appear to have been created using a legitimate commercial website builder. The product offers user management, payment, and file storage, which shows how legitimate infrastructure can be leveraged to create convincing fraudulent services.
What users should check before uploading data
Malwarebytes recommends that users not evaluate a service solely based on the appearance of the website or the presence of a “Sign in with Google”. The existence of an authentic sign-in process is not, in itself, proof that the application is legitimate.
Before making any payment or uploading files, it is important to check who is behind the service, whether they have verifiable contact information, and whether there are independent reviews for the product. Users should also carefully examine the developer name displayed during the Google sign-in process.
See also: AmnesiaStealer: Beware! New macOS malware
Pay special attention to documents and recordings
The most important protection measure is to not upload sensitive or confidential files to unknown AI platforms. This is especially true for corporate documents, financial data, customer data, and meeting recordings.
Finally, those who have linked an unknown service to their Google account can check the connected applications and remove those they do not recognize or no longer use.
This case shows that in the age of AI, phishing no longer needs to appear as an obviously poorly written email. It can take the form of a well-designed AI service, with a real Google login and a professional payment process. For businesses, therefore, verifying an AI service before using it is now a key part of digital security.
