Cybercriminals are increasingly leveraging artificial intelligence (AI) to enhance the effectiveness of their attacks by automating processes, scrutinizing extensive data for security flaws, and crafting sophisticated phishing schemes that are more challenging to detect.
Moreover, these malicious actors are using AI to generate convincing fake content that can circumvent traditional security defenses. Recent findings by cybersecurity experts at Cyble have revealed that cybercriminals are exploiting ChatGPT’s Sora AI to distribute malware.
Rising Threat: Sora AI Exploitation
Sora, an AI model from OpenAI introduced in February 2024 for transforming text into video, has sparked considerable excitement within the tech industry. Despite its unreleased status, cyber attackers are already eyeing its potential to revolutionize content creation for nefarious purposes.
Cyble Research and Intelligence Labs (CRIL) have uncovered a range of phishing sites masquerading as official Sora platforms. These fraudulent sites aim to trick users into downloading malware disguised as legitimate Sora software.
List of identified phishing sites:
- hxxps://sorics-ai[.]web.app
- hxxps://sora-6b494[.]web.app
- hxxps://sorics-ai.web[.]app
- hxxps://soraai-pro-kit[.]web.app
- hxxps://sora-openai-generation[.]com
- hxxps://openai-soravideo[.]com
- hxxps://opensora-ai.web[.]app
- hxxps://opensora[.]info
By late July 2024, cybercriminals had ingeniously orchestrated phishing attacks exploiting the unreleased Sora AI. They set up fake websites like “openai-soravideo[.]com” and “sora-openai-generation[.]com” and promoted them through compromised social media accounts.
These deceptive sites misled users into installing malware posing as Sora software. Notably, the Braodo Stealer malware targeted various browsers, including Chrome, Firefox, Edge, Opera, Brave, and Chromium, to harvest sensitive data, which was then transmitted via Telegram through API requests.
The malware employed techniques such as multi-level compression (zlib, bz2, gzip, lzma) and hexadecimal encoding to evade detection by antivirus programs. CRIL researchers reported that numerous users fell victim to these campaigns, often via sponsored advertisements, resulting in significant data breaches.
The Sora-themed malware campaign demonstrates a sophisticated approach to data theft. One variant captures screenshots, login credentials, cookies, and autofill data from multiple browsers, packaging the stolen information into a “.zip” file and sending it to the attacker’s Telegram chat through an API.
Another variant uses PyInstaller and PyArmor to obfuscate a Python script that downloads and executes “manifest.bat” from “https://sealingshop.click/bat/loc.” This malware collects sensitive information such as usernames, IP addresses, and browser data, and excludes users from certain regions. It then posts JSON-encoded data to an ngrok domain (hxxps://f34f-103-14-48-195.ngrok-free.app) via a POST request. Following data exfiltration, it installs cryptocurrency miners XMRig and lolMiner on the compromised system, demonstrating a dual focus on data theft and cryptojacking.
Recommendations for Mitigation
To protect against these threats, consider the following recommendations:
- Educate users about phishing risks and the dangers of unverified downloads.
- Verify the legitimacy of URLs and software before installation.
- Implement advanced threat detection systems.
- Monitor social media for signs of compromised accounts.
- Enforce multi-factor authentication (MFA) across all accounts and systems.
- Regularly back up and securely store important data.
- Employ web filtering solutions to block access to malicious sites.



