Google, in guidelines published in November to combat online crime, warned that scammers had begun distributing malicious applications disguised as VPN services. “Attackers typically impersonate trusted corporate and consumer VPN brands or use social engineering techniques, such as sexually explicit ads or geopolitical events, to target vulnerable users who need secure internet access,” the warning states.
Once installed, these apps introduce malware into gadgets, including information theft programs, remote access Trojans, and banking Trojans that steal sensitive data such as browsing history, personal messages, financial credentials, and cryptocurrency wallet information.
Another Google warning relates to artificial intelligence. Under the guise of popular AI services, scammers distribute malicious mobile and desktop applications, phishing sites that steal credentials, fleeceware applications with huge commissions, and malicious browser extensions.
“Cybercriminals are exploiting the widespread interest in AI tools by using them as bait for social engineering. Attackers create sophisticated scams by posing as popular artificial intelligence services, promising “free” or “exclusive” access to lure victims into a trap. <...> For victims, the consequences range from information theft by malware and financial losses to corporate network breaches and business account takeovers, ultimately eroding trust in the entire AI ecosystem.”