Thursday, 27 November 2025
29.1 C
Singapore
19.9 C
Thailand
27.5 C
Indonesia
27 C
Philippines

Kaspersky warns of AI-generated sites distributing remote access software in global campaign

Kaspersky reports a global campaign using AI-generated websites to distribute remote access tools and gain control of victims’ devices.

Kaspersky has uncovered a global campaign in which attackers are using AI-generated websites to distribute versions of the legitimate remote access tool Syncro. The activity spans Latin America, Asia Pacific, Europe and Africa. The sites are designed to appear trustworthy and often imitate well-known applications such as crypto wallets, antivirus software and password managers. Users are lured into downloading Syncro, which is then misused to gain control of their devices.

The campaign relies on search engine results and phishing emails to drive traffic to these sites. Many of the pages present themselves as offering security updates, trading apps or token migration tools. Once downloaded, the Syncro software operates as a genuine remote management tool, which makes it harder for standard security solutions to flag the activity as malicious. The tool gives attackers full access to the victim’s device, including the ability to view screens, access files and execute commands.

Kaspersky reports that scareware tactics form a key part of the campaign. Users may encounter false security warnings designed to pressure them into installing the remote access software. Once installed, the attackers aim to steal cryptocurrency by monitoring activity and exploiting the access granted through Syncro.

AI-generated websites create convincing but fraudulent experiences

The attackers use an AI website creation tool called Lovable to build professional-looking sites with domains that closely match common search queries. Rather than directly copying legitimate platforms, the pages create credible alternatives that appear authentic at first glance. One example includes sites referencing Polymarket, a prediction market platform, which are designed to convince users they are dealing with a trusted brand.

These fraudulent sites are promoted through search engines and targeted phishing emails. The emails often contain prompts urging users to install trading applications, update antivirus software or migrate digital tokens. Regardless of the scenario, the end result is the installation of Syncro, already configured to grant attackers remote access without alerting users or security tools.

Because the software is legitimate and typically used by IT teams, its presence does not automatically raise suspicion. This allows attackers to bypass common security measures and operate without immediate detection.

Kaspersky urges users to verify downloads and audit devices

Kaspersky has warned that the campaign reflects a growing trend in which legitimate software is repurposed for malicious activity, aided by AI-driven tools that allow cybercriminals to scale operations quickly. Vladimir Gursky, malware analyst at Kaspersky, said: “This campaign highlights the evolving threat landscape where legitimate tools are being weaponised through AI-driven deception. By automating the creation of high-quality fake sites, cybercriminals can scale attacks efficiently, preying on users’ trust in familiar brands and urgent warnings. It’s a stark reminder that even signed software from seemingly reputable sources demands scrutiny.”

The company recommends downloading software only from verified and official sources, especially when dealing with financial transactions or cryptocurrency management. Users should check URLs carefully, avoid installing remote access tools unless absolutely necessary, and review any such tools already present on their devices. Kaspersky also advises enabling anti-phishing features and carrying out regular security audits to reduce exposure to scareware and remote access-based threats.

Hot this week

Chrome tests new privacy feature to limit precise location sharing on Android

Chrome for Android tests a new privacy feature that lets websites access only approximate location data instead of precise GPS information.

Belkin Zootopia accessories you need before Zootopia 2 arrives

Belkin’s latest Zootopia collection brings fun designs and practical features to power banks, cables, cases and straps for everyday use.

LG launches world’s first 45-inch 5K2K OLED gaming monitor in Singapore

LG brings the world’s first 45-inch 5K2K OLED gaming monitor to Singapore with high refresh rates, Dual-Mode switching and advanced display technology.

Warner Music ends lawsuit against Suno after reaching new licensing agreement

Warner Music ends its lawsuit against Suno after securing a licensing deal that gives artists opt-in control over AI-generated music.

Qualcomm introduces Snapdragon 8 Gen 5 as streamlined alternative to Elite chipset

Qualcomm launches the Snapdragon 8 Gen 5 chipset, offering strong performance, AI features, and expected availability in devices within weeks.

Global mobile gaming ads surge in 2025 as AI and interactivity reshape engagement

Mobile gaming ads grew strongly in 2025 as AI-driven optimisation and interactive formats reshaped global user acquisition strategies.

POCO enters premium smartphone segment with new F8 series

POCO launches the F8 Ultra, F8 Pro, and two new tablets as it enters the premium flagship market with new performance and audio features.

Crunchyroll brings world-first premieres and major anime showcases to AFA Singapore 2025

Crunchyroll brings exclusive premieres, guest panels and a large interactive booth to AFA Singapore 2025.

Belkin UltraCharge Pro 3-in-1 Magnetic Charging Dock with Qi2 25W review: Fast, quiet and convenient charging

Belkin UltraCharge Pro 3-in-1 Magnetic Charging Dock with Qi2 25W offers fast, quiet and convenient wireless charging for iPhone, Apple Watch and AirPods.

Related Articles

Popular Categories