AI-Generated TikTok Videos Spread Malware

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Multiple reports reveal malware actors using AI-generated TikTok videos to spread infostealer malware. These deceptive videos instruct users to run commands that install malware, leading to data theft and privacy breaches. The campaign, leveraging trends like the ClickFix tactic, presents significant risks to personal and intellectual property security.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves AI-generated content (deepfake videos and AI-generated voice) used maliciously to deceive users into executing harmful commands, resulting in theft of credentials and sensitive information. This constitutes harm to individuals' property and privacy, fitting the definition of an AI Incident where AI system use directly leads to harm. The AI system's role is pivotal in enabling scalable, convincing social engineering attacks that cause realized harm.[AI generated]
AI principles
Privacy & data governanceRobustness & digital securityTransparency & explainabilityAccountabilityRespect of human rightsSafety

Industries
Media, social platforms, and marketingDigital securityConsumer services

Affected stakeholders
Consumers

Harm types
Human or fundamental rightsEconomic/PropertyReputational

Business function:
Marketing and advertisement

AI system task:
Content generation


Articles about this incident or hazard