Saturday, 13 December 2025
26 C
Singapore
22.1 C
Thailand
20.6 C
Indonesia
26.9 C
Philippines

Kaspersky warns of AI-generated sites distributing remote access software in global campaign

Kaspersky reports a global campaign using AI-generated websites to distribute remote access tools and gain control of victims’ devices.

Kaspersky has uncovered a global campaign in which attackers are using AI-generated websites to distribute versions of the legitimate remote access tool Syncro. The activity spans Latin America, Asia Pacific, Europe and Africa. The sites are designed to appear trustworthy and often imitate well-known applications such as crypto wallets, antivirus software and password managers. Users are lured into downloading Syncro, which is then misused to gain control of their devices.

The campaign relies on search engine results and phishing emails to drive traffic to these sites. Many of the pages present themselves as offering security updates, trading apps or token migration tools. Once downloaded, the Syncro software operates as a genuine remote management tool, which makes it harder for standard security solutions to flag the activity as malicious. The tool gives attackers full access to the victim’s device, including the ability to view screens, access files and execute commands.

Kaspersky reports that scareware tactics form a key part of the campaign. Users may encounter false security warnings designed to pressure them into installing the remote access software. Once installed, the attackers aim to steal cryptocurrency by monitoring activity and exploiting the access granted through Syncro.

AI-generated websites create convincing but fraudulent experiences

The attackers use an AI website creation tool called Lovable to build professional-looking sites with domains that closely match common search queries. Rather than directly copying legitimate platforms, the pages create credible alternatives that appear authentic at first glance. One example includes sites referencing Polymarket, a prediction market platform, which are designed to convince users they are dealing with a trusted brand.

These fraudulent sites are promoted through search engines and targeted phishing emails. The emails often contain prompts urging users to install trading applications, update antivirus software or migrate digital tokens. Regardless of the scenario, the end result is the installation of Syncro, already configured to grant attackers remote access without alerting users or security tools.

Because the software is legitimate and typically used by IT teams, its presence does not automatically raise suspicion. This allows attackers to bypass common security measures and operate without immediate detection.

Kaspersky urges users to verify downloads and audit devices

Kaspersky has warned that the campaign reflects a growing trend in which legitimate software is repurposed for malicious activity, aided by AI-driven tools that allow cybercriminals to scale operations quickly. Vladimir Gursky, malware analyst at Kaspersky, said: “This campaign highlights the evolving threat landscape where legitimate tools are being weaponised through AI-driven deception. By automating the creation of high-quality fake sites, cybercriminals can scale attacks efficiently, preying on users’ trust in familiar brands and urgent warnings. It’s a stark reminder that even signed software from seemingly reputable sources demands scrutiny.”

The company recommends downloading software only from verified and official sources, especially when dealing with financial transactions or cryptocurrency management. Users should check URLs carefully, avoid installing remote access tools unless absolutely necessary, and review any such tools already present on their devices. Kaspersky also advises enabling anti-phishing features and carrying out regular security audits to reduce exposure to scareware and remote access-based threats.

Hot this week

Singapore leads global third-party cyber risk maturity as supply-chain threats intensify

Singapore leads global third-party cyber risk maturity but faces rising supply-chain cyber threats, according to new BlueVoyant research.

Busways launches ultra-fast charging hub in northern Singapore

Busways has opened Singapore’s first ultra-fast charging hub in the north, supporting electric commercial and industrial fleets.

Grab signs partnership with Charge+ to expand EV charging network in Vietnam

Grab and Charge+ partner to expand Vietnam’s EV charging network and support the country’s shift towards green mobility.

Kirby Air Riders brings fast, chaotic racing to modern players

Kirby Air Riders offers fast, chaotic racing for quick sessions and modern short-attention-play styles.

Sony unveils 27-inch PlayStation monitor with DualSense charging hook

Sony unveils a 27-inch PlayStation monitor with a DualSense charging hook, HDR support, and variable refresh rates, set to release in 2026.

PlayStation introduces limited edition Genshin Impact DualSense controller

PlayStation announces a limited edition Genshin Impact DualSense controller for PS5, launching in Singapore on 21 January 2026.

PGL brings Counter-Strike 2 Major to Singapore in November 2026

PGL confirms the Counter-Strike 2 Major is coming to Singapore in November 2026, marking the first CS2 Major in Southeast Asia.

Denodo: Rethinking data architecture for AI agility and measurable ROI in Asia-Pacific

Denodo highlights how modern, composable data architectures powered by logical data management are helping Asia-Pacific enterprises accelerate AI adoption, ensure governance, and achieve measurable ROI.

Veeam completes acquisition of Securiti AI to build unified trusted data platform

Veeam completes its US$1.725 billion acquisition of Securiti AI to form a unified trusted data platform for secure and scalable AI adoption.

Related Articles

Popular Categories