{"id":25598,"date":"2024-12-18T07:10:19","date_gmt":"2024-12-18T15:10:19","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2024\/12\/18\/news-19327\/"},"modified":"2024-12-18T07:10:19","modified_gmt":"2024-12-18T15:10:19","slug":"news-19327","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2024\/12\/18\/news-19327\/","title":{"rendered":"AI-generated malvertising &#8220;white pages&#8221; are fooling detection engines"},"content":{"rendered":"\n<p>This is no secret, online criminals are leveraging artificial intelligence (AI) and large language models (LLMs) in their malicious schemes. While AI tends to be abused to trick people (i.e. deepfakes) in order to gain something, sometimes, it is meant to defeat computer security programs. <\/p>\n<p>With AI, this process has just become easier and we are seeing more and more cases of fake content produced for deception purposes. In the criminal underground, web pages or sites that are meant to be decoys are sometimes called &#8220;white pages,&#8221; as opposed to the &#8220;black pages&#8221; (malicious landing pages).<\/p>\n<p>In this blog post, we take a look at a couple of examples where threat actors are buying Google Search ads and using AI to create white pages. The content is unique and sometimes funny if you are a real human, but unfortunately a computer analyzing the code would likely give it a green check.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-fake-faced-executives\">Fake-faced executives<\/h2>\n<p>The first example is a phishing campaign targeting Securitas OneID. The threat actors are very cautious about avoiding detection by running ads that most of the time redirect to a completely bogus page unrelated to what one would expect, namely a phishing portal.<\/p>\n<p>It did cross our minds they could very well be trolling security researchers, but if that was truly the case, why not simply go for Rick Astley&#8217;s <em><a href=\"https:\/\/www.youtube.com\/watch?v=dQw4w9WgXcQ\">Never Gonna Give You Up<\/a><\/em>?<\/p>\n<figure class=\"wp-block-image aligncenter size-large\"><a href=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/12\/image_6bc7bb.png\"><img decoding=\"async\" loading=\"lazy\" width=\"854\" height=\"1111\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/12\/image_6bc7bb.png?w=787\" alt=\"\" class=\"wp-image-124843\" \/><\/a><\/figure>\n<p>The entire site was created with AI, including the team&#8217;s faces. While in the past, criminals would go for stock photos or maybe steal a Facebook profile, now it&#8217;s easier and faster to make up your own, and it&#8217;s even copyright-free!<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><a href=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/12\/image_11862e.png\"><img decoding=\"async\" loading=\"lazy\" width=\"847\" height=\"995\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/12\/image_11862e.png\" alt=\"\" class=\"wp-image-124851\" \/><\/a><\/figure>\n<p>When Google tries to validate the ad, they will see this cloaked page with pretty unique content and there is absolutely nothing malicious with it.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-parsec-and-the-universe\">Parsec and the universe<\/h2>\n<p>Our second example is another Google ad for Parsec this time, a popular remote desktop program used by gamers. <\/p>\n<p>It so happens that a <a href=\"https:\/\/www.space.com\/parsec\">parsec<\/a> is also an astronomical measurement unit and the threat actors (or should we say AI) went wild with it, creating a white page heavily influenced by Star Wars:<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><a href=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/12\/image_3fa1ec.png\"><img decoding=\"async\" loading=\"lazy\" width=\"869\" height=\"1001\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/12\/image_3fa1ec.png\" alt=\"\" class=\"wp-image-124835\" \/><\/a><\/figure>\n<p>The artwork, including posters, is actually quite nice, even for a non-fan.<\/p>\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><a href=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/12\/image_a03d73.png\"><img decoding=\"async\" loading=\"lazy\" width=\"363\" height=\"363\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/12\/image_a03d73.png\" alt=\"\" class=\"wp-image-124857\" style=\"width:895px;height:auto\" \/><\/a><\/figure>\n<p>Once again, this cloaked content is a complete diversion which will take detection engines for a ride.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-ai-vs-ai-humans-to-the-rescue\">AI vs AI: humans to the rescue<\/h2>\n<p>These are just some of the many examples of AI being misused. In the early days of deepfakes, one may remember companies already training AI to detect AI.<\/p>\n<p>There will naturally be content produced by AI for legitimate reasons. After all, nothing prohibits anyone from creating a website entirely with AI, simply because it&#8217;s a fun thing to do.<\/p>\n<p>In the end, AI can be seen as a tool which on its own is neutral but can be placed in the wrong hands. Because it is so versatile and cheap, criminals have embraced it eagerly.<\/p>\n<p>Ironically, it is quite straightforward for a real human to identify much of the cloaked content as just fake fluff. Sometimes, things just don&#8217;t add up and are simply comical. Do jokes trigger the same reaction in an AI engine as they would to a human? It doesn&#8217;t seem like it&#8230; yet.<\/p>\n<hr class=\"wp-block-separator has-text-color has-cyan-bluish-gray-color has-alpha-channel-opacity has-cyan-bluish-gray-background-color has-background is-style-wide\" \/>\n<p><strong>We don\u2019t just report on threats\u2014we remove them<\/strong><\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/for-home\">downloading Malwarebytes today<\/a>.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/cybercrime\/2024\/12\/ai-generated-malvertising-white-pages-are-fooling-detection-engines\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> With AI, it&#8217;s not only the sky that&#8217;s the limit, it&#8217;s the entire universe. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[10245,3108,4503,18051,11539,10531],"class_list":["post-25598","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-ai","tag-criminals","tag-cybercrime","tag-detection","tag-fake","tag-malvertising"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25598","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=25598"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25598\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=25598"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=25598"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=25598"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}