Millions Targeted by Malware Hidden in Fraudulent AI Ads on Facebook
Cybercriminals are using fake Facebook pages and ads to impersonate Kling AI, a popular AI tool for creating images and videos. These ads lead users to fake websites like klingaimedia[.]com, which claim to offer AI services but instead trick visitors into downloading malicious software. The malicious files are hidden in ZIP archives and install a remote access trojan (RAT) that allows attackers to control the victim’s device and steal sensitive information such as passwords and browser data. The malicious software avoids detection by hiding in legitimate Windows processes and includes a second-stage payload called PureHVNC, which targets crypto wallets and takes screenshots when banking apps are used.
How to Stay Safe:
- Avoid clicking on suspicious ads or links on social media.
- Always verify the official website before downloading any AI tools or software.
- Use trusted antivirus and anti-malware programs to detect and block threats.
- Keep your operating system, browser, and software up to date.
- Enable two-factor authentication (2FA) on your online accounts for added protection.
- Be cautious with ZIP file downloads, especially from unfamiliar sources.
- Report fake ads and pages to the social media platform to help stop their spread.
Source: https://thehackernews.com/2025/05/fake-kling-ai-facebook-ads-deliver-rat.html