AI Slop Is Now Attack Infrastructure
Note: Domains in this piece are defanged and refer to documented malicious infrastructure. Do not visit them.
If you search for “Luma AI blog” in Google, you might land on luma-ai[.]com. The page is a counterfeit AI software blog covering tutorials, comparisons, and other expected posts. The content is coherent enough to pass a quick skim. You click somewhere on the page.
That click — on a “read more,” a nav item, or anything else — triggers JavaScript that checks whether you have an ad blocker. It checks for 40 by name, plus regional blockers covering Chinese, Russian, Korean, and Arabic-language audiences. If it detects one, the script stops.
If it doesn’t detect a blocker, the site fingerprints the visitor and sends that information to attacker-controlled infrastructure, which decides whether to redirect them toward malware. Selected victims can end up with Vidar Stealer or Lumma Stealer, delivered through an installer designed to evade sandboxes and interfere with antivirus software.
This is what Zscaler ThreatLabz documented in June 2025: a campaign that built WordPress sites ranking for AI-tool search terms such as ChatGPT, Luma AI, Krea AI, Llama 2, and delivering infostealing malware.
This campaign is just one instance among many. In May 2025, Mandiant identified UNC6032, a Vietnam-nexus threat cluster running more than 30 counterfeit sites impersonating software tools being promoted through thousands of Facebook and LinkedIn ads that reached over 2.3 million users in the EU alone. Pillar Security tracked at least 20 distinct campaigns between February 2025 and March 2026 — and found that the first 10 weeks of 2026 had already produced more campaigns than all of 2025 combined. The discovery mechanism varies, but the targeting logic is the same: find people actively researching specific software, and meet them at the top of the results page.
For the attack to work, the content doesn’t need to be high-value, just plausible-looking. And AI can produce that type of content cheaply, at scale. Proofpoint has documented criminals using the AI website builder Lovable to create phishing, fraud and malware-delivery sites. SEO poisoning, malvertising redirectors, and infostealer delivery have existed for years, but they used to require significant time to exploit. Now, AI-driven cost structure makes running dozens of content sites viable.
Search Intent Is a Targeting Signal
The sites in the Zscaler-observed campaign targeted specific queries on purpose. People searching for “Luma AI blog” or “Krea AI” are probably not casual browsers. They're likely technically sophisticated enough to have disposable income, with credentials worth stealing, and possibly crypto wallets (Legion Loader's final payload was a browser extension built to steal cryptocurrency).
This is a form of behavioral targeting. Rather than buying access to an audience assembled by an advertising platform, the operator chooses search terms associated with the people it wants to reach and builds pages designed to capture that traffic.
Other campaigns have targeted victims though paid search and social advertising filters. But running a Google Ads campaign costs money, requires account verification, and is run through policy review. Black-hat SEO achieves the same audience selection at zero acquisition cost per click, with no intermediary capable of pulling the campaign and no paper trail connecting the landing page to whoever built it.
The capital goes into the pipeline that activates when a victim clicks: the C2 infrastructure, the ad blocker detection logic, the targeting server, the 800MB sandbox-evasion installer, and the dynamic decryption keys served at runtime by the Legion Loader C2.
AI Generation Closes the Economics
This attack has an obvious predecessor: the fake software site. Threat actors have long used counterfeit documentation sites and fake tool blogs. But before large language models could generate passable blog content at scale, building a convincing fake site required either human writers — real labor, rate-limited, expensive to maintain across multiple domains simultaneously — or compromised legitimate sites, with the associated operational risk and ongoing access maintenance.
A site built for this purpose needs to clear two bars: coherent enough that a search crawler doesn't immediately classify it as spam, and plausible enough that a visitor who lands there doesn't immediately leave. An LLM can clear both those bars with little cost.
Domain registration fees are the only real expenditure on the content side. If a site gets pulled, the replacement cost is just a few hours of work. The ThreatLabz IOC list shows four typosquatted domains active in the same campaign, which means the operators were already running parallel infrastructure, presumably expecting attrition.
The economics of site-level takedowns change completely when rebuilding is almost free. The takedown model that defenders and platforms relied on to disrupt these types of operations was optimized for a cost structure that no longer exists.
The attack pipeline behind the content is now amortized across however many site-spawning cycles the operators want to run — which is, in principle, unbounded.
The Pipeline Decides Who Gets the Payload
The ad blocker check is interesting because ad blocker presence is often a proxy for security posture. People running uBlock Origin, for example, are more likely to have updated browsers and security software. Filtering them out isn't just about avoiding blocked redirects — it also concentrates delivery on the lower end of the security-awareness distribution within an otherwise high-value audience.
The same targeting logic runs on the server side. The fingerprinted browser data is sent as an encrypted GET request to the attacker-controlled redirector domain, which ThreatLabz reports logged over 4.4 million hits since January 2025. The server makes a fresh decision for each visitor. On revisits, the site changes behavior, serving adware or other malware. The infrastructure is built to maximize yield per visit.
AI Slop As Camouflage
In a recent Krebs on Security piece on the DecryptAds transparency service, Zach Edwards of Infoblox observed that most malvertising doesn't happen on high-traffic destinations — it happens on lower-quality content farms, because those sites sign up for the cheapest available ad partners without scrutiny. The same permissive ad networks that don't vet their publishers don't vet the ads they serve either.
The Fengwo Group case, documented by Bitsight in July 2026, represents the logical endpoint of this model. Fengwo didn't build AI content farms to attract organic traffic, but rather to serve as click targets for their own botnet. H96 streaming devices they'd compromised spoofed themselves as Samsung, Huawei, and Xiaomi phones and clicked ads on machine-generated sites covering finance, health, gaming, food, and music. The sites displayed ads only to the spoofed H96 device profile. No real user was ever meant to visit them.
In this case, AI content generation is working as pure infrastructure camouflage. The sites needed to look like sites because ad networks require something that looks like a publisher. The content was the minimum viable facade — and minimum viable is now achievable at zero additional cost per site.
The Bottom Line
AI slop typically gets framed as a content quality problem: bad information crowding out good, search results degrading, models training on junk. Those are real problems, but the ThreatLabz and Fengwo cases show that AI slop is also a security risk. The pipeline isn’t new, but AI has made it easy and cheap to run.
Sources
Manisha Ramcharan Prajapati & Meghraj Nandanwar, Zscaler ThreatLabz. "Black Hat SEO Poisoning Search Engine Results For AI to Distribute Malware," June 2025: https://www.zscaler.com/blogs/security-research/black-hat-seo-poisoning-search-engine-results-ai-distribute-malware
Mandiant Threat Defense. "Text-to-Malware: How Cybercriminals Weaponize Fake AI-Themed Websites," May 2025: https://cloud.google.com/blog/topics/threat-intelligence/cybercriminals-weaponize-fake-ai-websites
Pillar Security. "AI Coding Tools Under Fire: Mapping the Malvertising Campaigns Targeting the Vibe Coding Ecosystem," March 2026: https://www.pillar.security/blog/ai-coding-tools-under-fire-mapping-the-malvertising-campaigns-targeting-the-vibe-coding-ecosystem
Brian Krebs. "Who's Tracking You? Use This New Service to Find Out," August 2026: https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/
Brian Krebs. "Read This Before You Buy That TV Streaming Stick," July 2026: https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
Pedro Falé, Bitsight TRACE. Fengwo Group / H96 research, July 2026: https://www.bitsight.com/blog/fuyao-operation-unveiling-sophisticated-ad-fraud-residential-proxy-scheme