Security researchers have identified a surge in malicious applications and scams leveraging the branding of popular AI platforms such as ChatGPT, DALL·E, and WhatsApp to deceive users, particularly in the United States. Investigations revealed that some of these apps, available on third-party app stores, masquerade as legitimate AI tools but are in fact either adware or full-fledged spyware. For example, a fake DALL·E 3 app was found to display only advertisements while pretending to generate images, and a counterfeit WhatsApp Plus app operated as spyware, harvesting sensitive data including contacts, SMS, and device accounts, enabling identity theft and financial fraud. These findings highlight the growing risk of users being tricked into installing harmful software under the guise of trusted AI brands.
In a related incident, a deepfake video of Nvidia CEO Jensen Huang was used to promote a cryptocurrency scam during a fake Nvidia GTC keynote stream on YouTube. The AI-generated hoax attracted nearly 100,000 viewers, significantly outpacing the legitimate event, and was even promoted above the official stream in search results. This demonstrates the increasing sophistication and reach of AI-powered scams, where attackers exploit both the popularity of AI brands and the capabilities of generative AI to create convincing fraudulent content, posing significant risks to user privacy, financial security, and trust in digital platforms.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
A spyware campaign involving malicious apps masquerading as ChatGPT, DALL·E, and WhatsApp was reported as targeting users in the United States. The apps were described as carrying spyware functionality while posing as legitimate software.
A fraudulent YouTube stream impersonated Nvidia GTC and used an AI-generated deepfake of CEO Jensen Huang to promote a cryptocurrency scam. The fake broadcast reportedly drew about 100,000 viewers and was promoted above Nvidia's legitimate event.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcetomshardware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.