{"id":56724,"date":"2024-08-01T00:00:00","date_gmt":"2024-08-01T00:00:00","guid":{"rendered":"urn:uuid:d001398c-888d-ee48-b76d-6e0483ed8150"},"modified":"2024-08-01T00:00:00","modified_gmt":"2024-08-01T00:00:00","slug":"social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\/","title":{"rendered":"Social Media Malvertising Campaign Promotes Fake AI Editor Website for Credential Theft"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/social-media-malvertising-976:Large?qlt=80\"><!-- OneTrust Cookies Consent Notice start for trendmicro.com --><!-- OneTrust Cookies Consent Notice end for trendmicro.com --> <head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width\"> <meta name=\"description\" content=\"We uncovered a malvertising campaign where the threat actor hijacks social media pages, renames them to mimic popular AI photo editors, then posts malicious links to fake websites.\"> <meta name=\"robots\" content=\"index,follow\"> <meta name=\"keywords\" content=\"malware,cyber crime,research,phishing,cyber threats,endpoints,articles, news, reports\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge,chrome=1\"> <meta name=\"template\" content=\"article1withouthero\"> <meta property=\"article:published_time\" content=\"2024-08-01\"> <meta property=\"article:tag\" content=\"phishing\"> <meta property=\"article:section\" content=\"research\"> <link rel=\"icon\" type=\"image\/ico\" href=\"\/content\/dam\/trendmicro\/favicon.ico\"> <link rel=\"canonical\" href=\"https:\/\/www.trendmicro.com\/en_us\/research\/24\/h\/malvertising-campaign-fake-ai-editor-website-credential-theft.html\"> <title>Social Media Malvertising Campaign Promotes Fake AI Editor Website for Credential Theft | Trend Micro (US)<\/title> <link href=\"https:\/\/fonts.googleapis.com\/css?family=Open+Sans:300,300i,400,400i,600\" rel=\"stylesheet\">\n<link href=\"\/\/customer.cludo.com\/css\/296\/1798\/cludo-search.min.css\" type=\"text\/css\" rel=\"stylesheet\"> <link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch.min.css\" type=\"text\/css\">\n<link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendmicro\/clientlibs\/trendmicro-core-2\/clientlibs\/header-footer.min.css\" type=\"text\/css\"> <meta property=\"og:url\" content=\"https:\/\/www.trendmicro.com\/en_us\/research\/24\/h\/malvertising-campaign-fake-ai-editor-website-credential-theft.html\"><br \/>\n<meta property=\"og:title\" content=\"Social Media Malvertising Campaign Promotes Fake AI Editor Website for Credential Theft\"><br \/>\n<meta property=\"og:description\" content=\"We uncovered a malvertising campaign where the threat actor hijacks social media pages, renames them to mimic popular AI photo editors, then posts malicious links to fake websites.\"><br \/>\n<meta property=\"og:site_name\" content=\"Trend Micro\"><br \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/24\/social-media-malvertising-976.png\"><br \/>\n<meta property=\"og:locale\" content=\"en_US\"> <meta name=\"twitter:card\" content=\"summary_large_image\"><br \/>\n<meta name=\"twitter:site\" content=\"@TrendMicro\"><br \/>\n<meta name=\"twitter:title\" content=\"Social Media Malvertising Campaign Promotes Fake AI Editor Website for Credential Theft\"><br \/>\n<meta name=\"twitter:description\" content=\"We uncovered a malvertising campaign where the threat actor hijacks social media pages, renames them to mimic popular AI photo editors, then posts malicious links to fake websites.\"><br \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/24\/social-media-malvertising-976.png\"> <\/head> <body class=\"articlepage page basicpage context-business\" id=\"readabilityBody\" readability=\"47.237561588252\"> <!-- Page Scroll: Back to Top --> <a id=\"page-scroll\" title=\"VerticalPageScroll\" href=\"javascript:jumpScroll($(this).scrollTop());\"> <span class=\"icon-chevron-up\"><\/span> <\/a> <!-- \/* Data Layers *\/ --> <\/p>\n<div class=\"root responsivegrid\">\n<div class=\"aem-Grid aem-Grid--12 aem-Grid--default--12 \">\n<div class=\"articleBodyNoHero aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"research-layout article container\" role=\"contentinfo\">\n<article class=\"research-layout--wrapper row\" data-article-pageid=\"1647171147\">\n<div class=\"col-xs-12 col-md-12 one-column\">\n<div class=\"col-xs-12 col-md-12\" readability=\"8.7743732590529\">\n<div class=\"article-details\" role=\"heading\" readability=\"37.047353760446\"> <span class=\"article-details__bar\" role=\"img\"><\/span> <\/p>\n<p class=\"article-details__display-tag\">Phishing<\/p>\n<p class=\"article-details__description\">We uncovered a malvertising campaign where the threat actor hijacks social media pages, renames them to mimic popular AI photo editors, then posts malicious links to fake websites. <\/p>\n<p class=\"article-details__author-by\">By: Jaromir Horejsi <time class=\"article-details__date\">August 01, 2024<\/time> <span>Read time:&nbsp;<\/span><span class=\"eta\"><\/span> (<span class=\"words\"><\/span> words) <\/p>\n<div class=\"article-details__icons\"> <!--Add This--> <\/p>\n<div class=\"a2a_kit a2a_default_style\" data-a2a-icon-color=\"#717172\"> <a class=\"a2a_dd addthis_link\" href=\"https:\/\/www.addtoany.com\/share\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch\/resources\/img\/share-more.svg\" class=\"svg-icon\" alt=\"Share\"> <\/a> <a class=\"a2a_button_print addthis_link\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch\/resources\/img\/printer.svg\" class=\"svg-icon\" alt=\"Print\"> <\/a> <\/div>\n<p> <!--Add to Folio--> <!--Subscribe--> <\/div>\n<\/div><\/div>\n<\/p><\/div>\n<hr class=\"research-layout-divider\"> <main class=\"main--content col-xs-12 col-lg-8 col-lg-push-2\"> <\/p>\n<div class=\"richText\" readability=\"40.715871516297\">\n<div readability=\"27.470949456778\">\n<ul>\n<li><span class=\"rte-red-bullet\">In this blog entry, we examine how threat actors hijack social media pages, rename them to resemble a legitimate AI photo editor, then post malicious links to fake websites, which are boosted via paid ads.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">The attackers use spam messages with phishing links to steal admin credentials. These links lead to fake account protection pages that trick users into providing their login information.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Once the attacker gains control of the page, ads are posted promoting the AI photo editor, leading victims to download an endpoint management utility disguised as the photo editor.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">The ITarian software is used to execute additional payloads like Lumma Stealer, which exfiltrates sensitive data such as cryptocurrency wallet files, browser data, and password manager databases.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Cybercriminals are exploiting the popularity of AI tools by using them as lures for malicious activities, which includes phishing scams, deepfakes, and automated attacks.<\/span><\/li>\n<\/ul>\n<p>We discovered a malvertising campaign involving a threat actor that steals social media pages (typically related to photography), changing their names to make them seem connected to popular AI photo editors. The threat actor then creates malicious posts with links to fake websites made to resemble the actual website of the legitimate photo editor. To increase traffic, the perpetrator then boosts the malicious posts via paid ads.<\/p>\n<p>The abuse of paid Facebook promotions for malicious activities is not new. In 2023, we published two blog posts on profile stealers, which were implemented either as <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/h\/profile-stealers-spread-via-llm-themed-facebook-ads.html\">browser extensions<\/a> or <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/i\/analyzing-a-facebook-profile-stealer-written-in-node-js.html\">standalone application<\/a>s.<\/p>\n<p>When victims open the malicious websites, they are tricked into visiting the download section and installing the package, which is \u2014 as expected \u2014 not a photo editor, but a legitimate endpoint management utility using a malicious configuration. After successful installation, this utility allows for remote device management. The attacker can then abuse the tool\u2019s features to download and execute credential stealers, which ultimately leads to the exfiltration of sensitive data and credentials.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a class=\"bs-modal\" id=\"4698da\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/h\/social-media-malvertising-campaign\/fig1.png\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/h\/social-media-malvertising-campaign\/fig1.png\" alt=\"Figure 1. Attack chain\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 1. Attack chain<\/figcaption><\/div>\n<\/figure><\/div>\n<div>\n<div class=\"richText\" readability=\"36.5\">\n<div readability=\"18\">\n<h2><span class=\"body-subhead-title\"><\/span><\/h2>\n<p>To gain control of the target social media page, the threat actor will first send messages to the administrator containing phishing links, which can either be direct links or &nbsp;personalized link pages (linkup.top, bio.link, s.id, and linkbio.co, among others). Sometimes these links abuse Facebook\u2019s open redirect URL, &gt;, to seem more legitimate.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/h\/social-media-malvertising-campaign\/fig2.png\" alt=\"Figure 2. Spam message with phishing link\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 2. Spam message with phishing link<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<p>The sender of the message will typically use an empty profile with randomly generated usernames followed by a few digits.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/h\/social-media-malvertising-campaign\/fig3.png\" alt=\"Figure 3. The profile of the spammer \"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 3. The profile of the spammer <\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<h2><span class=\"body-subhead-title\"><\/span><\/h2>\n<p>If operators of the targeted Facebook pages click on the personalized links, they are presented with a screen similar to those shown below.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/h\/social-media-malvertising-campaign\/fig4a.png\" alt=\"Figure 4. Examples of personalized links\"> <\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/h\/social-media-malvertising-campaign\/fig4b.png\" alt=\"Figure 4. Examples of personalized links\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 4. Examples of personalized links<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"35\">\n<div readability=\"15\">\n<p>Clicking on the \u201c<i>Verify Your Information Here<\/i>\u201d links lead to a fake account protection page, which in several subsequent steps, asks users for the information necessary to log in and take over their account, such as their phone number, email address, birthday, and password.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/h\/social-media-malvertising-campaign\/fig5.png\" alt=\"Figure 5. Phishing page, first step\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 5. Phishing page, first step<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/h\/social-media-malvertising-campaign\/fig6.png\" alt=\"Figure 6. Phishing page, second step\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 6. Phishing page, second step<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/h\/social-media-malvertising-campaign\/fig7.png\" alt=\"Figure 7. Phishing page, third step\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 7. Phishing page, third step<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"34.492753623188\">\n<div readability=\"14.782608695652\">\n<p>After the target provides all the needed information, the attacker then steals their profile and starts posting malicious ads.<\/p>\n<h2><span class=\"body-subhead-title\"><\/span><\/h2>\n<p>After taking control of the Facebook pages, the threat actor will start posting advertisements that links to the fake AI photo editor domain. In this case, the name of the legitimate photo editor being abused is <a href=\"https:\/\/www.evoto.ai\/home\">Evoto<\/a>.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/h\/social-media-malvertising-campaign\/fig8.png\" alt=\"Figure 8. Malicious advertisements, allegedly promoting the \u201cEvoto photo editor\u201d, with different ads being written from different Facebook pages\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 8. Malicious advertisements, allegedly promoting the \u201cEvoto photo editor\u201d, with different ads being written from different Facebook pages<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<h2><span class=\"body-subhead-title\"><\/span><\/h2>\n<p>The fake photo editor web page looks very similar to the original one, which helps in tricking the victim into thinking that they are downloading a photo editor. The reality however, is that they are actually downloading and installing an endpoint management software.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/h\/social-media-malvertising-campaign\/fig9.png\" alt=\"Figure 9. Download page for the fake photo editor\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 9. Download page for the fake photo editor<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"34.5\">\n<div readability=\"14\">\n<p>Interestingly enough, the JavaScript responsible for downloading the package contains statistics in a variable called <i>download_count<\/i>. At the time of writing this report, there are approximately 16,000 hits for Windows binary and 1,200 hits for the MacOS version (which only redirects to <i>apple.com<\/i> and does not return any binary).<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a class=\"bs-modal\" id=\"f084c9\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/h\/social-media-malvertising-campaign\/fig10.png\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/h\/social-media-malvertising-campaign\/fig10.png\" alt=\"Figure 10. Downloaded JavaScript with statistics\"> <\/a> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 10. Downloaded JavaScript with statistics<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"38.151174668029\">\n<div readability=\"25.740551583248\">\n<h2><span class=\"body-subhead-title\"><\/span><\/h2>\n<p>When victims execute the installation MSI package (disguised as a photo editor installer), their devices are immediately <a href=\"https:\/\/help.itarian.com\/topic-459-1-1005-14887-Enroll-Windows-Endpoints.html?af=7639\">enrolled for management<\/a>, giving the threat actor full access to remotely control the device.<\/p>\n<p>As shown in the link from Figure 9, the downloaded file is an <a href=\"https:\/\/www.itarian.com\/\">ITarian installer<\/a>. ITarian is a free <a href=\"https:\/\/www.itarian.com\/rmm-software.php\">endpoint management<\/a> software. Threat actor signs up for a free account, registers a subdomain (seen in the <a href=\"https:\/\/help.itarian.com\/topic-459-1-1005-14776-Appendix-1b---Endpoint-Manager-Services---IP-Nos,-Host-Names-and-Port-Details---US-Customers.html?af=7639#us_cc\">subdomain<\/a> <i>itstrq<\/i> in Figures 9 and 10), and creates an installation <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/msi\/windows-installer-portal\">MSI package<\/a>. This installation package needs to be distributed to victims for installation.<\/p>\n<p>Interestingly, the MSI package itself does not contain any malicious components.&nbsp; It does not even contain any file with a malicious configuration. Instead, we get the installer file name format: <b>em_&lt;token&gt;_installer.msi<\/b>. When querying &gt;, we receive the malicious enrollment configuration.https:\/\/mdmsupport.comodo.com\/enroll\/resolve\/token\/&lt;token&gt;, we receive the malicious enrollment configuration.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/h\/social-media-malvertising-campaign\/fig11.png\" alt=\"Figure 11. Malicious ITarian configuration\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 11. Malicious ITarian configuration<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p>When the device is successfully enrolled for remote management, a few scheduled tasks are executed. The scheduled tasks are of the <i>Python_Procedure<\/i> type and contain<\/p>\n<p>1) A simple downloader in Python to download and execute an additional payload.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/h\/social-media-malvertising-campaign\/fig12.png\" alt=\"Figure 12. Python script to download and execute another payload\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 12. Python script to download and execute another payload<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"32.5\">\n<div readability=\"10\">\n<p>Of note is the user agent value \u201c<i>Magic Browser<\/i>\u201d. The additional payload is typically Lumma Stealer and its binary is usually encrypted with PackLab Crypter.<\/p>\n<p>2) A simple script to exclude disk C: from being scanned with Microsoft Defender.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/h\/social-media-malvertising-campaign\/fig13.png\" alt=\"Figure 13. Python script to exclude the entire disk C: from being scanned with Microsoft defender\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 13. Python script to exclude the entire disk C: from being scanned with Microsoft defender<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"35.127906976744\">\n<div readability=\"19.412790697674\">\n<p>The script modifies Windows Defender settings by calling <a href=\"https:\/\/learn.microsoft.com\/en-us\/powershell\/module\/defender\/add-mppreference?view=windowsserver2022-ps\"><i>Add-MpPreference -ExclusionPath<\/i><\/a>.<\/p>\n<h2><span class=\"body-subhead-title\"><\/span><\/h2>\n<p>The final payload is Lumma Stealer, which has its initial C&amp;C communication &nbsp;characterized by two consecutive POST requests to the <b>\/api<\/b> URL path with the <a href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/HTTP\/Methods\/POST\"><i>x-www-form-urlencoded<\/i><\/a> content type. The first request content is <i>act=life<\/i>, followed by the second requests content, <i>\u201cact=recive_message&amp;ver=&lt;version&gt;&amp;lid=&lt;id&gt;&amp;j=\u201d<\/i> (sic!), which returns a Base64 encoded stealer configuration.<\/p>\n<p>The first 32 bytes of the debased buffer is a XOR key, while the remaining bytes are the encrypted configuration. The decrypted configuration is in JSON format and lists everything the stealer is supposed to steal.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/h\/social-media-malvertising-campaign\/fig13.png\" alt=\"Figure 13. The decrypted stealer\u2019s configuration\"> <\/p>\n<div class=\"caption-image-container \"><figcaption>Figure 13. The decrypted stealer\u2019s configuration<\/figcaption><\/div>\n<\/figure><\/div>\n<div class=\"richText\" readability=\"31.944312796209\">\n<div readability=\"10.648104265403\">\n<p>The targeting of social media users for malicious activities highlights the importance of robust security measures to protect account credentials and prevent unauthorized access. This includes the following best practices:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Users should enable multi-factor authentication (MFA) on all social media accounts to add an extra layer of protection against unauthorized access.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Users should regularly update and use strong, unique passwords for social media accounts.<\/span><\/li>\n<\/ul>\n<ul>\n<li><span class=\"rte-red-bullet\">Organizations should educate their employees on the dangers of phishing attacks and how to recognize suspicious messages and links.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Users should always verify the legitimacy of links, especially those asking for personal information or login credentials.<\/span><\/li>\n<\/ul>\n<ul>\n<li><span class=\"rte-red-bullet\">Both organizations and individual users should monitor their accounts for any unusual behavior, such as unexpected login attempts or changes to account information.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Organizations should consider using security solutions that can detect abnormal account activities.<\/span><\/li>\n<\/ul>\n<ul>\n<li><span class=\"rte-red-bullet\">Organizations should consider employing endpoint technologies such as <a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/detection-response.html\">Trend Vision One\u2122<\/a>&nbsp;, which provides multilayered protection and behavior detection, helping block malicious tools before they can do any damage.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">For other types of AI tool abuse, specifically those involving deepfakes, organizations can consider using Trend&#8217;s <a href=\"https:\/\/www.trendmicro.com\/en_us\/forHome\/products\/free-tools.html\">Deepfake Inspector<\/a>, which helps protect against scammers using AI face-swapping technology during live video calls.&nbsp; Users can activate the tool when joining video calls and can be alerted to the presence of AI-generated content or deepfake scams.&nbsp;<\/span><\/li>\n<\/ul>\n<p>The following tactics and techniques are a subset of the <a href=\"https:\/\/attack.mitre.org\/\">MITRE ATT&amp;CK list<\/a>.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"richText\" readability=\"30.706896551724\">\n<div readability=\"9.448275862069\">\n<p>The indicators of compromise for this entry can be found <a href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/h\/social-media-malvertising-campaign\/ioc-social-media-malvertising%20-campaign-fake-ai-editor-website-credential-theft.txt\">here<\/a>.&nbsp;<\/p>\n<p>Meanwhile, the decrypted config file can be found <a href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/h\/social-media-malvertising-campaign\/lumma-cfg-importancedopz.shop-beautified.json\">here<\/a>.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<section class=\"tag--list\">\n<p>Tags<\/p>\n<\/section>\n<p> <\/main> <\/article>\n<\/div>\n<\/div><\/div>\n<\/div>\n<p> <!-- \/* Core functionality javascripts, absolute URL to leverage Akamai CDN *\/ --> <!--For Modal-start--> <\/p>\n<p> <span>sXpIBdPeKzI9PC2p0SWMpUSM2NSxWzPyXTMLlbXmYa0R20xk<\/span> <\/p>\n<p> <!--For Modal-end--> <\/body> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/24\/h\/malvertising-campaign-fake-ai-editor-website-credential-theft.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We uncovered a malvertising campaign where the threat actor hijacks social media pages, renames them to mimic popular AI photo editors, then posts malicious links to fake websites. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9521,9511,9508,9513,9577,9509],"class_list":["post-56724","post","type-post","status-publish","format-standard","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-cyber-crime","tag-trend-micro-research-cyber-threats","tag-trend-micro-research-endpoints","tag-trend-micro-research-malware","tag-trend-micro-research-phishing","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Social Media Malvertising Campaign Promotes Fake AI Editor Website for Credential Theft 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Social Media Malvertising Campaign Promotes Fake AI Editor Website for Credential Theft 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2024-08-01T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/social-media-malvertising-976:Large?qlt=80\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Social Media Malvertising Campaign Promotes Fake AI Editor Website for Credential Theft\",\"datePublished\":\"2024-08-01T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\\\/\"},\"wordCount\":1375,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trendmicro.scene7.com\\\/is\\\/image\\\/trendmicro\\\/social-media-malvertising-976:Large?qlt=80\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Cyber Crime\",\"Trend Micro Research : Cyber Threats\",\"Trend Micro Research : Endpoints\",\"Trend Micro Research : Malware\",\"Trend Micro Research : Phishing\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\\\/\",\"name\":\"Social Media Malvertising Campaign Promotes Fake AI Editor Website for Credential Theft 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trendmicro.scene7.com\\\/is\\\/image\\\/trendmicro\\\/social-media-malvertising-976:Large?qlt=80\",\"datePublished\":\"2024-08-01T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trendmicro.scene7.com\\\/is\\\/image\\\/trendmicro\\\/social-media-malvertising-976:Large?qlt=80\",\"contentUrl\":\"https:\\\/\\\/trendmicro.scene7.com\\\/is\\\/image\\\/trendmicro\\\/social-media-malvertising-976:Large?qlt=80\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Social Media Malvertising Campaign Promotes Fake AI Editor Website for Credential Theft\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Social Media Malvertising Campaign Promotes Fake AI Editor Website for Credential Theft 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\/","og_locale":"en_US","og_type":"article","og_title":"Social Media Malvertising Campaign Promotes Fake AI Editor Website for Credential Theft 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2024-08-01T00:00:00+00:00","og_image":[{"url":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/social-media-malvertising-976:Large?qlt=80","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Social Media Malvertising Campaign Promotes Fake AI Editor Website for Credential Theft","datePublished":"2024-08-01T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\/"},"wordCount":1375,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\/#primaryimage"},"thumbnailUrl":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/social-media-malvertising-976:Large?qlt=80","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Cyber Crime","Trend Micro Research : Cyber Threats","Trend Micro Research : Endpoints","Trend Micro Research : Malware","Trend Micro Research : Phishing","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\/","url":"https:\/\/www.threatshub.org\/blog\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\/","name":"Social Media Malvertising Campaign Promotes Fake AI Editor Website for Credential Theft 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\/#primaryimage"},"thumbnailUrl":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/social-media-malvertising-976:Large?qlt=80","datePublished":"2024-08-01T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\/#primaryimage","url":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/social-media-malvertising-976:Large?qlt=80","contentUrl":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/social-media-malvertising-976:Large?qlt=80"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/social-media-malvertising-campaign-promotes-fake-ai-editor-website-for-credential-theft\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"Social Media Malvertising Campaign Promotes Fake AI Editor Website for Credential Theft"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/56724","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=56724"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/56724\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=56724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=56724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=56724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}