PULSE NAME
The Sting of Fake Kling: Facebook Malvertising Lures Victims to Fake AI Generation Website
WHITE AlienVault 2025-05-21 Modified: 2025-06-20
53
IOCs
HIGH VOLUME
A threat actor has orchestrated a sophisticated malvertising campaign impersonating Kling AI, a popular AI-powered image and video synthesis tool. The attackers use counterfeit Facebook pages and paid ads to drive traffic to a convincing fake website. Users are tricked into downloading malicious files disguised as AI-generated media, which are actually executable loaders. These loaders employ advanced evasion techniques, including .NET Native AOT compilation, and deploy infostealers with extensive monitoring capabilities. The campaign has a global reach, particularly targeting users in Asia, and exploits the growing popularity of AI content generation platforms. The malware focuses on stealing credentials, session tokens, and monitoring crypto-related activities across multiple browsers and applications.
Indicators of Compromise (7 / 53 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 0c074d5f3072888a97e2503fea633f804ee33c62 2025-05-21
FileHash-SHA1 2234e8cbbc834081c50d11d42fb18e3b51b93ea6 2025-05-21
FileHash-SHA1 271ac50c3c082238cc4f3815df75b5dd9f844c2c 2025-05-21
FileHash-SHA1 629d786f59e5c6481e0a439b0d0818b5ad2459db 2025-05-21
FileHash-SHA1 78acce2974629596f35686c8d975986d16a0fdfe 2025-05-21
FileHash-SHA1 a296727e8e17f5292c58f23d17ef55c16072841e 2025-05-21
FileHash-SHA1 cd0924b008e5c246ee37d960c41a37cb57cf1a90 2025-05-21
References (1)