Websites offering fake subscriptions to AI transcription tools, image generators, and other digital assistants could be putting enterprise data at risk, according to researchers at Malwarebytes.
The sites impersonate AI products with solid reputations, including GPT-6 Astra, DaVinci Resolve, PixAI and OpenCut, in addition to some that no longer exist (such as Omegle, a chat service shut down in 2023) or are less reputable.
All the fake websites were polished and incorporate genuine Google authentication elements inviting users to “Sign in with Google” to enhance credibility on the path to charging visitors’ payment cards anything from $10 a month to as much as $2,000 for a year’s access to the promised AI and software services.
“The sites we examined did not use fake password forms or push malware downloads,” Malwarebytes researchers said in a blog post describing their discovery. But some of the sites asked users to upload documents, recordings, or other files in order to unlock the advertised services.
The danger for enterprises is if would-be customers of such services think they’re getting a good deal for their departmental budget and don’t want to involve IT in the buying process. Shadow IT is bad enough when the products are legitimate, but in these cases there’s no knowing where the data gathered will end up.
Malwarebytes’ researchers suspect that all the fake subscription sites it identified are run by the same person or group, since they were all created using the same website creation kit based on identical underlying files and with closely related developer email addresses shared across them.
The website creation kit is a legitimate commercial offering that provides account management, billing, file storage and other administrative functions, Malwarebytes said, noting its makers claim it can launch a website in an hour and that, after a one-time purchase, additional templates cost only about $2 each.
The fake sites use genuine Google sign-in pages rather than fake password forms. Visitors enter their credentials on Google’s website and the applications request basic information such as their name, email address and profile picture. Malwarebytes said the sites it examined did not request access to Gmail or Google Drive.
Google’s consent screen generally identifies the application requesting access and provides developer details, Malwarebytes noted. But on the fake websites, that screen displayed free webmail addresses for the developer contacts instead of addresses belonging to the well-known AI services promised. In the case of the unfamiliar AI brands, the sites provide little independently verifiable information about the businesses selling the subscriptions, the researchers added.
Look past the polish
Malwarebytes recommends that users look beyond a site’s design and the presence of familiar authentication options when deciding whether an AI service is legitimate. These include checking who operates the service, looking for verifiable company information and examining the developer details shown during Google authentication.
It also warned users not to upload sensitive documents, recordings or other data to unfamiliar AI services, particularly when the business behind the site cannot be independently verified.
For services connected through Google, users can review the connections in their Google Account and remove services they no longer trust or recognize to prevent future access.
This article first appeared on Computerworld.
No Responses