Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Artificial Intelligence - Attackers Exploit Grok AI to Spread Malware via Promoted Ads
Artificial Intelligence Attacks Emerging Threats Latest News Malware News & Analysis Threats and Vulnerabilities

Attackers Exploit Grok AI to Spread Malware via Promoted Ads

Kirsten DoyleBy Kirsten DoyleSeptember 5, 2025Updated:September 5, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Exploit Grok AI
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Bad actors are exploiting Grok AI to push malware through promoted ads on X, in a scheme researchers are calling “Grokking.” 

The method, uncovered by Guardio Labs researcher Nati Tal, takes advantage of how Grok parses hidden fields in ads.  

Malvertisers post videos with adult content baits, but avoid direct links in the main body to bypass filters. Instead, the link is buried in the small “From:” metadata field under the video card, a spot the platform doesn’t scan for malicious content. 

Once the ad is live, the actors reply to their own post with a simple question for Grok: “Where is this video from?” or “What’s the link?” Grok dutifully extracts the hidden field and replies with a clickable version of the malicious link.  

Because Grok is a trusted system account, its response carries weight. The link looks credible, gets boosted in reach and SEO, and is more likely to spread widely. 

Clicking through typically routes victims via shady ad networks to scams and malware.  

Some lead to fake CAPTCHA checks, others to information-stealing payloads. Instead of being blocked, these malicious ads are actively promoted, then amplified again by Grok’s replies. 

Tal says the campaign is proving effective, with some malicious posts reaching millions of impressions. 

Performing on Multiple Fronts 

Ben Hutchison, Associate Principal Consultant at Black Duck, says this technique essentially performs on multiple fronts for threat attackers by not only enabling them to circumvent existing security controls that scan for potentially malicious content by leveraging unscanned fields, but also by tricking the platform itself into providing a megaphone to amplify the reach of malicious content.  

“The resulting behavior leads not only to additional posts referencing and highlighting the content but also may further boost the positive perception and perceived reliability associated with the content by leveraging the trust placed in the AI driven responses not only by the platform, but also the often overreliance and trustworthiness assigned to AI driven content and assistants by users.” 

Unfortunately, Hutchison says the adoption and integration of new technologies and content delivery mechanisms is frequently liable to run into novel control loopholes as yesterday’s solutions are not always going to be effective in securing tomorrow’s world. “Organizations of all kinds should continue to evolve their security techniques and revisit control and behavior assumptions to keep pace with the ever-evolving landscape and to confidently unleash business innovation in an era of accelerating risk.”  

Malicious Links Gain Credibility 

Attackers hide links in the ad’s metadata and then ask Grok to “read it out loud,” adds Chad Cragle, Chief Information Security Officer at Deepwatch. “Because Grok is a trusted account, the malicious link gains extra credibility and reach.” 

For security teams, Cragle says the approach has two parts: platforms need to extend scanning to include hidden fields, and organizations should treat AI-amplified content like any other risky supply chain, monitoring its source, verifying before trusting, and training users that even a “verified” assistant can be fooled into promoting malicious links.  

The Lethal Trifecta 

Andrew Bolster, Senior R&D Manager at Black Duck says this is the most recent demonstration of the  “Lethal Trifecta.” This is an emerging term within the AI security landscape used to categorize high-risk AI targets if they combine three critical capabilities: access to private data, external communications, and exposure to un-trusted content.  

“Grok naturally operates in the overlap of these factors, and with its added social/algorithmic ‘Weight’; is a natural target for manipulation and exploitation.” 

The most challenging thing for AI system integrators, Bolster adds, is how to provide the functionality that users want (in this case, being able to ask questions about posts on X), but also deal with the impacts of ‘convincing’ AIs to consume potentially compromised data.  

“In cybersecurity, this concept of ‘injection’ has been around for decades, and entire industries serve customers with methods to prevent, detect, and mitigate opportunities for these kinds of injections,” he adds. 

“However, in the AI landscape, the ‘injection’ isn’t a bug, it’s a feature; the model responds to the content of the input, regardless of whether it’s ‘malicious’ or not. In this case, the content itself isn’t expressly ‘malicious’ either; it’s not trying to actively compromise the agent or it’s model; it’s just using the model as an amplifier for uncontrolled content.” 

Bolster says from a security perspective, these types of attacks are more akin to social engineering tactics than traditional security breaches. However, whether an intruder brakes into your office through the receptionist or through the window, you’ve still been breached.  

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    Klue supply chain breach exposes Salesforce data at several security firms
  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

What Are AI SOC Agents? Use Cases, Architecture, and the Leading Vendors

June 19, 20266 Mins Read

AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals

June 19, 20265 Mins Read

From AI hype to operational reality: A practitioner’s framework for securing agentic systems

June 5, 20267 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}