PULSE NAME
The Sting of Fake Kling: Facebook Malvertising Lures Victims to Fake AI Generation Website
WHITE AlienVault 2025-05-21 Modified: 2025-06-20
53
IOCs
HIGH VOLUME
A threat actor has orchestrated a sophisticated malvertising campaign impersonating Kling AI, a popular AI-powered image and video synthesis tool. The attackers use counterfeit Facebook pages and paid ads to drive traffic to a convincing fake website. Users are tricked into downloading malicious files disguised as AI-generated media, which are actually executable loaders. These loaders employ advanced evasion techniques, including .NET Native AOT compilation, and deploy infostealers with extensive monitoring capabilities. The campaign has a global reach, particularly targeting users in Asia, and exploits the growing popularity of AI content generation platforms. The malware focuses on stealing credentials, session tokens, and monitoring crypto-related activities across multiple browsers and applications.
Indicators of Compromise (7 / 53 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 29a6477b4ad97037bbce1df27e822e27 2025-05-21
FileHash-MD5 3cee96215d2694759dda5674cd275354 2025-05-21
FileHash-MD5 52a6f1dc6d6b357b33a7e840245832b5 2025-05-21
FileHash-MD5 66d2d615671994f9d61e863901eac5c1 2025-05-21
FileHash-MD5 a5c7a3e1af9d646b9d9db34523c5af8e 2025-05-21
FileHash-MD5 f95fcb33d0ae6ed046ae627149561361 2025-05-21
FileHash-MD5 fda73d77c77e9b80b0f5f4aba68e6a1d 2025-05-21
References (1)