Beware of AI tools being advertised on Facebook. They could be malware in disguise.

AI photo editors are trendy right now, making them the perfect target for hackers and scammers.
By Matt Binder  on 
Facebook logo
Bad actors are weaponizing the AI craze to spread malware through ads run on stolen Facebook pages. Credit: Serene Lee/SOPA Images/LightRocket via Getty Images

Generative AI is in a bit of a hype bubble in the tech industry right now. As such, new and potentially interesting AI tools are regularly popping up, inviting everyday users to try out the latest new AI software.

However, just because AI is big right now, doesn't mean every AI tool that users come across is legitimate. In fact, it's quite the opposite. Bad actors regularly look to take advantage of whatever is popular at the moment. And the current AI trend makes potential AI consumers particularly vulnerable to hackers and scammers. 

Case in point, a new report from Trend Micro has found that bad actors are utilizing a tried and true method of weaponizing Facebook ads to lure AI users into downloading malware disguised as AI photo editing tools.

Malware hiding as AI software

Mashable has previously reported on how online criminals utilize hacked Facebook pages in order to scam victims. 

Mashable Light Speed
Want more out-of-this world tech, space and science stories?
Sign up for Mashable's weekly Light Speed newsletter.
By signing up you agree to our Terms of Use and Privacy Policy.
Thanks for signing up!

Scammers have used these Facebook ads to advertise products that they never send to buyers. Hackers have rebranded stolen Facebook pages to look like official accounts from companies like Google and even Facebook parent company Meta itself in order to trick users into downloading malware.

Bad actors are now updating this strategy and posing as AI image-editing tools to spread malware.

According to the Trend Micro report, scammers are tricking page owners into handing over their login credentials through basic phishing campaigns. Once the scammers have access to an already established account, they rebrand the Facebook Page as an AI photo editing tool. In the case analyzed by Trend Micro, the scammers posed as Evoto, a real AI photo editing tool.

After rebranding the stolen pages as Evoto, the scammers then began running paid Facebook ads through those pages, sending users to a fake website where users could supposedly download the AI photo editing tool. Of course, the target isn't downloading AI software. In this case, the unaware victim is downloading endpoint management software which gives the attacker remote access to their device. From there, the hacker can steal the user's login credentials as well as other sensitive data.

Social media users should proceed with caution when it comes to any unknown downloadable software being promoted via advertisements on a platform. They could very well be malware in disguise.


Recommended For You
Android users, beware! Text message stealing malware is targeting smartphones to gain access to users' data
Android logo on smartphone

Amazon's 'Remarkable' Alexa will actually be Claude in disguise, report claims
Amazon Alexa

5 back-to-school tech tools for boosting productivity
a smiling woman holding a pair of headphones and e-tablet

I tried on the new large Pixel Watch 3 and it's stunning — just beware of this one thing
Woman wearing Pixel Watch 3


Trending on Mashable
Wordle today: Answer, hints for October 11
a phone displaying Wordle

NYT Connections today: Hints and answers for October 11
A phone displaying the New York Times game 'Connections.'

Astronomers just found a galaxy way too advanced for its time
Galaxy forming in the early universe

Tesla’s surprise announcements: Robovan and Optimus
Two images side by side. On the left is a screenshot of the Robovan. On the right is a Tesla promotional image of an Optimus robot serving someone a drink.

'The Platform 2's twisty ending, explained
A close-up of a topless, bald man holding a lit lighter.
The biggest stories of the day delivered to your inbox.
This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.
Thanks for signing up. See you at your inbox!