Scammers Exploit Grok AI With Video Ad Scam to Push Malware on X
Scammers Exploit Grok AI With Video Ad Scam to Push Malware on X
Have you noticed how malicious links are now being "ππ«π¨π€π€ππ"?
X won't allow links in promoted posts to fight malvertising. Yet scammers love the challenge and trick Xβs AI to amplify the same links that should've been blocked!
This is "ππ«π¨π€π€π’π§π "
Malvertisers run βvideo cardβ promoted posts with mostly sketchy βadultβ content baits (how these even pass X's review is a mystery!)
The malicious link is hidden in the tiny "π π«π¨π¦:" field below the video player. There is no malicious link scanning whatsoever on X! Yet, it is still barely noticeable at this spot. It is not really a good malvertising practice, just yet...
Meanwhile, these posts reach 100k to 5M+ impressions through paid promotion! π°
Then comes the twist. Scammers turn to ππ¬π€ ππ«π¨π€!
They ask something like: "ππ‘ππ«π π’π¬ ππ‘π’π¬ π―π’πππ¨ ππ«π¨π¦?" π
Grok reads the promoted post and finds the βFromβ field, using it in its reply π This time, the malicious link is fully visible, clickable, and impossible to miss. Adding to that, it is now amplified in SEO and domain reputation - after all, it was echoed by Grok on a post with millions of impressions! π€―
So what happened?
A malicious link that X explicitly prohibits in ads (and should have blocked entirely!) suddenly appears in a post by the system-trusted Grok account, sitting under a viral promoted thread and spreading straight into millions of feeds and search results!
π The system meant to enforce restrictions gets bypassed, and the AI itself becomes the amplifier! π€
And the links? They lead through shady ad networks, monetizing clicks with βdirect linksβ that are known to push Fake captcha scam, Info stealer malware and other shady grey-area content
Really, grok? Donβt you check your links before you βgrokβ them?