The EvilAI campaign exploits trusted applications to spread malicious software

Threat actors have begun to use seemingly legitimate artificial intelligence tools to distribute malware, affecting various industries such as manufacturing, government, and healthcare in countries like the U.S., India, and several European nations. This campaign, known as EvilAI, is an active and evolving effort in which attackers disguise malicious software as productivity tools or AI-enhanced applications. The great danger for all types of organizations Cybercriminals use professional interfaces and valid digital signatures to make these applications appear legitimate, making it difficult for users and security tools to detect them. Among the […]

Threat actors have begun using seemingly legitimate artificial intelligence tools to distribute malware, affecting various industries such as manufacturing, government, and health in countries like the U.S., India, and several European nations. This campaign, known as EvilAI, is an active and evolving effort in which attackers disguise malicious software as productivity tools or AI-enhanced applications.

The great danger for all types of organizations

Cybercriminals use professional interfaces and valid digital signatures to make these applications appear legitimate, making it difficult for users and security tools to detect them. Among the distributed programs are AppSuite, Epi Browser, and PDF Editor, which act as vehicles to conduct extensive reconnaissance and exfiltrate sensitive data from the victims’ browsers.

The propagation techniques are diverse and include the use of newly registered websites that mimic provider portals, malicious advertising, and SEO manipulation to promote download links on forums and social media. Some attacks have been facilitated with certificates from companies in Panama and Malaysia, and it has been documented that malware developers have used multiple certificates to make their software appear legitimate over the years.

Recent investigations have revealed that the actors behind applications like OneStart and ManualFinder share the same server infrastructure, suggesting a malware-as-a-service model. Additionally, advanced techniques such as Unicode encoding and the use of the NeutralinoJS framework are being employed to conceal malicious activities and evade detection.

This remarkable approach to camouflage and evasion capabilities has allowed attackers to gain access to systems, raising alarms about the increasing sophistication of digital threats and the exploitation of user trust.

Share of Search: the new KPI that every marketing professional should know

The Share of Search has consolidated itself as a key performance indicator essential in the field of marketing, measuring the percentage of searches for a brand compared to its competitors. This KPI is crucial for determining consumer visibility and interest, as an increase in Share of Search often anticipates future market growth. A KPI to keep in mind from now on Unlike Market Share and Share of Voice, which focus on past sales and advertising respectively, Share of Search captures intent […]

The Share of Search has established itself as a key performance indicator essential in the field of marketing, measuring the percentage of searches for a brand compared to its competitors. This KPI is crucial for determining visibility and consumer interest, as an increase in Share of Search often anticipates future growth in the market.

A KPI to keep in mind from now on

Unlike Market Share and Share of Voice, which focus on past sales and advertising respectively, Share of Search captures the genuine intention of the consumer through searches. This implies that an increase in this indicator not only reflects a rise in brand awareness but can also drive future sales, as consumers tend to seek information about a product before making a purchase.

The rise of AI-based search tools is transforming the way brand visibility is discovered and evaluated. This is relevant because, although changes in search engines may complicate the measurement of Share of Search, this KPI remains a tangible reflection of consumer interest.

Marketing specialists must closely monitor the Share of Search trends of their competitors to adjust strategies before they affect their market share. This includes optimizing related search terms and employing strategic advertising campaigns. Additionally, accurate measurement of Share of Search can provide valuable insights that will drive informed and proactive decision-making, before changes in consumer perception negatively impact sales figures.

Ultimately, tools like Google Trends and Semrush can facilitate the tracking of Share of Search, allowing brands to identify improvement opportunities and effectively capture consumer attention.

The first actress created by AI has arrived to revolutionize Hollywood

Artificial intelligence continues its advance in the entertainment industry with the arrival of Tilly Norwood, the first creation of the AI talent studio Xicoia. This innovative studio, fundamentally a spin-off of the production company Van der Velden, is designed to explore the creative possibilities offered by advanced technology in acting. Who needs actors when you have bits? Tilly Norwood has captured the attention of multiple talent agents, highlighting her potential to secure a place in the competitive entertainment industry. Eline Van der Velden, actress, comedian, and producer, shared this information during a panel at the […]

Artificial intelligence continues its advance in the entertainment industry with the arrival of Tilly Norwood, the first creation of the AI talent studio Xicoia. This innovative studio, fundamentally a spin-off of the production company Van der Velden, is designed to explore the creative possibilities offered by advanced technology in acting.

Who needs actors when you have bits?

Tilly Norwood has captured the attention of multiple talent agents, highlighting her potential to secure a spot in the competitive entertainment industry. Eline Van der Velden, actress, comedian, and producer, shared this information during a panel at the Zurich Summit, an integral part of the Zurich Film Festival. Her statement underscores the increasing search for creative solutions based on artificial intelligence, which are beginning to redefine acting and film production.

The launch of Xicoia and the introduction of Norwood could mark the beginning of a new era in the representation of digital characters. With continuous improvements in AI technology, Tilly represents a significant advancement, raising new debates about authenticity and the role of artificial intelligence in storytelling. As the industry begins to embrace these new tools, a fertile ground opens up for the exploration of novel concepts in acting.

As interest in Tilly Norwood grows, many are wondering how far this innovation can go. Through the exhibition of AI-built characters on the big screen, fans will be able to see firsthand how AI can contribute to the industry, although there are also those who have reservations about the impact this could have on traditional human actors. This evolution in entertainment is just beginning, and the future of Tilly Norwood will be a testament to the opportunities and challenges that artificial intelligence will bring.

The North Korean hackers who were about to steal thousands of cryptocurrencies thanks to a trojan

Recent investigations have uncovered a sophisticated cyberattack campaign attributed to threat actors linked to North Korea, called Contagious Interview. This campaign focuses on software developers working on Windows, Linux, and macOS operating systems, and is particularly aimed at those involved in cryptocurrency and Web3 projects. The cybersecurity firm ESET has identified this group, known as DeceptiveDevelopment, which uses a series of tools and tactics to infiltrate companies and steal sensitive information. An intangible threat Among the tools used is a Trojan called AkdoorTea, which is distributed via scripts […]

Recent investigations have uncovered a sophisticated cyberattack campaign attributed to threat actors linked to North Korea, called Contagious Interview. This campaign targets software developers working on Windows, Linux, and macOS operating systems, particularly those involved in cryptocurrency and Web3 projects. The cybersecurity firm ESET has identified this group, known as DeceptiveDevelopment, which employs a range of tools and tactics to infiltrate companies and steal sensitive information.

An Intangible Threat

Among the tools used is a Trojan called AkdoorTea, which is distributed via Windows batch scripts and resembles another implant known as NukeSped. The campaign has been designed to lure victims with attractive job offers on platforms like LinkedIn and Upwork. Victims are instructed to complete programming exercises that, unbeknownst to them, install malware on their systems.

Criminals have adopted a clever approach by impersonating recruiters, presenting well-paid jobs, and once the target expresses interest, they lead them to interact with fake sites that simulate a video assessment, but actually serve to facilitate the installation of malware. In this process, various malware variants have been identified, such as BeaverTail and InvisibleFerret, designed to steal information and manage cryptocurrencies.

Additionally, there are indications that the Contagious Interview campaign is related to other fraudulent initiatives by North Korean IT workers, which have been ongoing since 2017. Reports suggest that these actors often combine identity theft with digital tools, classifying them as a hybrid threat that merges traditional criminal operations and cybercrime.

Software developers are advised to be alert to suspicious job offers and to verify the legitimacy of any communication received regarding potential job opportunities.

Implementing AI in the workplace is pointless if you don't have a dedicated team for it

In the field of digital marketing, the emergence of language models (LLMs) like ChatGPT, Claude, and Gemini has transformed the way industry professionals develop content and manage complex tasks. Each of these models has unique characteristics that make them more suitable for different tasks, allowing teams to establish adaptive and efficient workflows. With AI, never trust Gemini, for example, excels in deep research and the creation of well-founded content, making it ideal for complex projects. Its integration into the Google ecosystem facilitates […]

In the field of digital marketing, the emergence of language models (LLMs) like ChatGPT, Claude, and Gemini has transformed the way industry professionals develop content and manage complex tasks. Each of these models presents unique features that make them more suitable for different tasks, allowing teams to establish adaptive and efficient workflows.

Never trust AI

Gemini, for example, excels in deep research and the creation of well-founded content, making it ideal for complex projects. Its integration into the Google ecosystem facilitates secure access to tools like Drive, Gmail, and Calendar, enhancing data analysis capabilities. With an academic approach, Gemini is the preferred assistant for creating professional and well-documented content.

On the other hand, Claude shines in the realm of creative writing. With a massive context window that allows for handling up to 200,000 tokens, it proves to be a great ally in developing long and cohesive narratives, ideal for extensive articles or books. Its ability to generate content that sounds human has received praise on various platforms, making it a favorite among content creators.

ChatGPT, on the other hand, acts as a general assistant. Its versatility makes it perfect for everyday tasks and brainstorming sessions. Although it may lack the necessary depth for complex content, its ability to generate quick responses and create visual elements with DALL-E makes it a valuable tool. However, some users have pointed out that its responses can often feel simplified.

This focus on specialization allows marketing teams to use artificial intelligence more effectively, choosing the LLM that best fits each task. By observing and combining the strengths of Gemini, Claude, and ChatGPT, a universe of possibilities opens up to improve the quality and efficiency of content in the digital market.

You have up your sleeve to be a marketing whiz: AI Decisioning

Artificial intelligence (AI) is transforming the marketing landscape, enabling hyper-personalized real-time experiences that surpass the limitations of traditional automation. However, many marketers still face challenges due to poor data quality and the lack of optimization of their customer data platforms (CDP). This dilemma is exacerbated in a changing environment, where the expectations for results at the level of AI do not always align with the actual capabilities of the tools used. Is AI viable in marketing? AI Decisioning represents a significant evolution in marketing, moving beyond […]

Artificial intelligence (AI) is transforming the marketing landscape, enabling hyper-personalized experiences in real-time that surpass the limitations of traditional automation. However, many marketers still face challenges due to poor data quality and the lack of optimization of their customer data platforms (CDP). This dilemma is exacerbated in a changing environment, where the expectations for AI-level results do not always align with the actual capabilities of the tools used.

Is AI viable in marketing?

AI Decisioning represents a significant evolution in marketing, moving beyond static rule-based automation. While traditional automation relies on predefined instructions, AI Decisioning learns from real-time behavior to recommend the best course of action, dynamically personalizing the customer experience. This allows brands to deliver the right content, channels, and moments that respond to the ever-evolving preferences of consumers.

However, the effectiveness of these tools largely depends on the quality of the data. Many marketers still struggle to unify and optimize their data sets, which limits their ability to fully leverage AI features. According to experts, it is crucial to set clear goals and systematically manage data preparation to implement a truly effective AI Decisioning system.

Marketers remain essential in the process, bringing their understanding of customer behavior and adapting strategies based on insights derived from AI. However, it is vital that marketing professionals do not confuse advanced automation with true AI; the key is to identify tools that genuinely use AI rather than those that are merely enhanced versions of traditional automation.

What are Artificial Intelligence agents (and how to manage them)

In today’s business environment, the management of non-human identities (NHI), such as service accounts and artificial intelligence (AI) agents, has become increasingly complex and risky. Many organizations now report having hundreds of these accounts operating in the background, many of which have been created automatically and lack clear ownership. This proliferation of identities has posed serious security challenges, as most of these NHIs were not designed with security in mind. Managing and succeeding, it all starts with that A concerning aspect is that, often, the number of non identities […]

In today’s business environment, the management of non-human identities (NHI), such as service accounts and artificial intelligence (AI) agents, has become increasingly complex and risky. Many organizations now report having hundreds of these accounts operating in the background, many of which have been created automatically and lack clear ownership. This proliferation of identities has posed serious security challenges, as most of these NHIs were not designed with security in mind.

Manage and succeed, it all starts with beginning

A concerning aspect is that often, the number of non-human identities exceeds that of human users by a ratio of more than 80 to 1. These IHN are often created during the deployment of services and are not properly tracked or documented, becoming “shadow identities.” Without a complete inventory, organizations may be leaving an unknown and expanding attack surface.

The lack of access controls and the assignment of excessive permissions are common problems that pose a significant risk. IHNs, which often have broad permissions to avoid disruptions, become valuable targets for attackers. With fixed credentials and no context, it can even be difficult to detect malicious activities before it’s too late.

To mitigate these risks, organizations are beginning to adopt proactive approaches to identity governance. Identity security platforms like Okta are emerging as effective solutions, providing a unified inventory of identities and helping to implement scalable controls to reduce exposure to threats. Recognizing and treating IHNs as critical access points is a necessary step to prevent potential exploits in the future.

Is it the future or just a simple curiosity? 'Whispers' comes to demonstrate the future of AI in series

The series Whispers was presented at the Busan Asian Contents & Film Market, where its innovative approach to AI-driven storytelling was highlighted. This new project seeks to explore how AI can transform stories, offering viewers a unique interactive experience. During the presentation, an interactive teaser was shown that allowed attendees to glimpse the potential of telling stories in a dynamic and personalized way, adapting to user interactions. Choose your own adventure Bernie Su, the Emmy-winning producer known for his work on The Lizzie Bennet Diaries, leads this initiative […]

The series Whispers was presented at the Busan Asian Contents & Film Market, where its innovative approach to AI-driven storytelling was highlighted. This new project aims to explore how AI can transform stories, offering viewers a unique interactive experience. During the presentation, an interactive teaser was shown that allowed attendees to glimpse the potential of telling stories in a dynamic and personalized way, adapting to user interactions.

Choose Your Own Adventure

Bernie Su, the Emmy-winning producer known for his work on The Lizzie Bennet Diaries, leads this initiative with the intention of innovating in traditional narrative formats. His motivation to create a series centered on AI comes from a deep desire to explore new paths in storytelling. “The storyteller for me is the one who can change and adapt”, Su commented, emphasizing how AI could act as a powerful tool to evolve the way stories are told today.

The event in Busan not only served as a platform to present Whispers, but it also reflected a growing interest in the use of artificial intelligence in the industry of entertainment. With the advancement of technology, many creators are considering the possibilities that AI offers to enhance interaction and personalization in the narrative experience. This type of project could mark the beginning of a new era in content production, where stories are not only told but actively experienced by viewers.

The rise of fake captchas: a new weapon for cybercriminals

Recent reports from Trend Micro have revealed that artificial intelligence platforms are being used by cybercriminals to create and host fake CAPTCHA pages. This innovative technique is transforming the way phishing campaigns are conducted, allowing attackers to implement more sophisticated and effective strategies in a short period of time. Prove that you are not a robot CAPTCHAs, known for their use in verifying online users, are now being manipulated to deceive potential victims. By utilizing AI tools, criminals not only generate pages that […]

Recent reports from Trend Micro have revealed that artificial intelligence platforms are being used by cybercriminals to create and host fake CAPTCHA pages. This innovative technique is transforming the way phishing campaigns are conducted, allowing attackers to implement more sophisticated and effective strategies in a short period of time.

Prove that you are not a robot

CAPTCHAs, known for their use in verifying online users, are now being manipulated to deceive potential victims. By utilizing AI tools, criminals not only generate pages that appear legitimate but also optimize the process, thereby improving the effectiveness of their attacks. This poses a significant threat, as users can be easily led to provide sensitive information under the illusion that they are interacting with a trustworthy site.

The speed and scale at which these campaigns can be developed, thanks to AI capabilities, represent a greater challenge for cybersecurity measures. Reports suggest that the creation of fake CAPTCHAs can increase the success rates of digital scams, making them harder for users to detect and, potentially, less vulnerable to the management of technology companies seeking to protect their platforms.

The use of this technology in the wrong hands underscores the urgent need for both organizations and users to remain vigilant and educate themselves about the latest threats in the realm of phishing. With the continuous advancement of AI and its inclusion in criminal strategies, cybersecurity faces an unprecedented challenge that requires a proactive and coordinated response.