Fake AI video ads on Facebook spreading malware to millions

Cybercriminals are exploiting the Artificial Intelligence video boom by running fake ads on Facebook that infect users with malware.

Amid a rapid rise in enthusiasm for Artificial Intelligence-based video creation tools, cybercriminal groups are seizing on the trend to distribute malware through fraudulent ads on Facebook. According to Google’s threat intelligence arm Mandiant, these attackers are crafting advertisements that appear to promote reputable video generators such as Canva’s Dream Lab, Luma AI, and Kling AI. Instead of leading to authentic services, these ads redirect users to counterfeit websites rigged with malicious software.

The malicious campaign, identified as UNC6032 and attributed to threat actors from Vietnam, has been operating since mid-2024 and relies on an evolving network of more than 30 fake domains. The fake sites distribute a range of threats, including Python-based information stealers and remote access backdoors, allowing the attackers to harvest sensitive information. Tactics include regularly switching domain names and uploading new ads on a near-daily cycle, helping the group skirt Meta’s detection and takedown efforts. Although the majority of incidents occur on Facebook, some activity has spread to LinkedIn. Internal figures obtained by Mandiant indicate the campaign’s massive reach: in the European Union alone, just 120 of these ads were delivered to over 2.3 million users.

The group’s ultimate objective goes far beyond simple ad clicks; harvested data includes login credentials, credit cards, browser cookies, and Facebook account details, all intended for secondary exploitation. While Meta has already removed many fraudulent ads flagged since 2024, the persistence and agility of UNC6032 pose an ongoing challenge. Security researchers urge users to avoid clicking on Artificial Intelligence tool ads within social media platforms; instead, they recommend searching for the official website of the desired tool directly to significantly reduce the risk of malware exposure and data theft.

66

Impact Score

Europe weighs technology sovereignty push amid internal debate

Europe is preparing a new policy push to reduce reliance on major technology platforms, but internal disagreements are shaping the scope and pace of the effort. The Artificial Intelligence Development Act is due to be unveiled on June 3 after repeated delays.

EU Artificial Intelligence Act omnibus deal delays high-risk rules

A provisional EU agreement would push back key high-risk Artificial Intelligence Act deadlines while keeping major transparency duties on track for 2 August 2026. The deal also adds a new ban on non-consensual intimate imagery and child sexual abuse material generated by Artificial Intelligence systems.

UK and EU Artificial Intelligence regulatory outlook for May 2026

The UK is moving ahead with targeted Artificial Intelligence measures in policing, online safety, cyber security and copyright policy, while the EU is refining how the EU Artificial Intelligence Act will apply in practice. Consultations, new offences and implementation deadlines are shaping the next phase of compliance on both sides.

Contact Us

Got questions? Use the form to contact us.

Contact Form

Clicking next sends a verification code to your email. After verifying, you can enter your message.