Fake Kling AI campaign marks new era of cyberattacks

The fake campaign impersonating Kling AI ushers in a new era of sophisticated cyberattacks putting millions of users at risk.
The fake campaign impersonating Kling AI ushers in a new era of sophisticated cyberattacks putting millions of users at risk.

 


A new wave of cyberattacks leverages the popularity of generative artificial intelligence platforms to distribute malware via fraudulent social media ads.

Researchers at Check Point Research have identified a malicious operation impersonating Kling AI, an image and video synthesis tool with over six million users worldwide.

Social Media Deception.

During the first months of 2025, at least 70 fraudulent ads on Facebook were detected promoting Kling AI.

These ads directed users to a counterfeit website meticulously designed to replicate the platform’s authentic environment.

Visitors were invited to generate images using artificial intelligence on that page.

However, instead of receiving a generated image, victims downloaded a disguised file containing a remote access trojan (RAT), which grants attackers full control over the infected device.

The malicious file appeared as a legitimate image, with names such as Imagen_generada_2025.jpg and icons resembling common multimedia files.

Opening the file activated software that silently installed itself on the system, ensuring it executed on every reboot.

This technique, known as file masquerading, aims to disguise dangerous executables as harmless elements.

Full Device Control.

In a second attack phase, the RAT activated, allowing cybercriminals to remotely operate the victim’s computer.

This type of malware is designed to steal credentials, spy on browser activity, and intercept information from password-storing extensions.

The trojan code included Vietnamese messages, suggesting a possible link to threat groups from that region specializing in social media fraud.

Researchers warn this campaign represents an evolution in cyberattack techniques, combining sophisticated social engineering with the use of emerging technologies as bait.

Ángel Salazar, Channel Security Engineering Manager for Latin America at Check Point Software, adds:

”The popularity of generative artificial intelligence is being exploited by cybercriminals who seek to take advantage of the trust users place in these tools. The Kling AI campaign shows how increasingly realistic deception techniques combine with sophisticated malware to compromise personal data. It is essential that organizations have proactive security solutions and that users become increasingly aware of these emerging risks.”

Prevention and Awareness.

In response to these threats, Check Point Software emphasizes the need to combine advanced protection technologies with awareness campaigns to help users recognize potential scams.

Solutions such as the company’s Threat Emulation and Harmony Endpoint provide coverage against a wide range of attack vectors, detecting and blocking threats before they can execute.


Share:
Hosting Web
Most Read