Skip to content
Threat Feed

Tag

Malvertising

4 briefs RSS
high threat

Adversarial Indirect Prompt Injection Tools Emerge in Underground Forums

Malicious actors are actively developing and advertising tools for Indirect Prompt Injection (IDPI) on underground forums, leveraging hidden prompts within various mediums like emails, PDFs, calendar invites, and malvertising to manipulate Large Language Models (LLMs) and AI agents, potentially leading to unintended behaviors such as data exfiltration or bypassing content moderation systems.

exploited Large Language Models +4 prompt-injection ai-security llm malvertising phishing
4t
high threat

Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor

Operation FlutterBridge is a malvertising campaign targeting macOS users with the new FlutterShell backdoor, which uses malicious desktop applications for adware distribution and provides backdoor capabilities such as command execution and file system manipulation, with some variants using AI summarization for data exfiltration.

Chrome +5 CL-CRI-1089 malvertising macos backdoor
3r 1t 8i
high advisory

Malvertising Campaign Abuses Google Ads and Claude.ai for macOS Malware Delivery

Attackers are using Google Ads malvertising and weaponized Claude.ai shared chats to trick macOS users into downloading and executing malware, leading to credential theft and system compromise.

Google Ads +1 malvertising macos infostealer googleads claudeai
3r 1t 3i
high advisory

Fake Claude AI Site Spreads Beagle Backdoor via DLL Sideloading

A malicious website impersonating Anthropic's Claude AI platform delivers the Beagle backdoor through a DLL sideloading attack, leveraging a compromised G DATA antivirus updater to execute malicious code.

Claude +2 malvertising dll sideloading backdoor beagle donutloader
2r 2t 3i