Graphing Fake “Kling AI” Malvertising Map, Block, Protect
Malvertisements promising AI tools and “instant video/article editing” are a lucrative bait for attackers.

Graphing Fake Kling AI Malvertising Lures That Promise AI, Deliver Infostealers
Malvertisements promising AI tools and “instant video/article editing” are a lucrative bait for attackers. Our Graphing Fake Kling AI Malvertising service maps the whole campaign infrastructure (ad → landing → loader → HVNC/remote implant → plugins → C2) so your SOC can see the chain, prioritize choke points, and stop the campaign before broad damage occurs.
Below we expand on how these fake Kling AI campaigns lure victims, what happens after a click (infostealer infection chains), detection signals to hunt for, and practical mitigations, plus the IOC table you provided for immediate blocking.
How the fake Kling AI lure works social engineering and delivery

Attackers craft convincing, attractive ad content and landing pages that promise free or discounted AI services: “Auto‑edit your video in seconds,” “Generate professional scripts,” or “Exclusive Kling AI beta access.” The lure relies on three psychological levers:
Authority & novelty: AI tools and platform-sounding brand names (e.g., KlingAI) imply legitimacy and advanced capability.
Urgency & scarcity: “Limited time beta,” “Join now,” prompts rushed decisions and lowers user scrutiny.
Social proof: Fake Facebook pages, likes, or comments add perceived credibility and reduce suspicion.
Typical user flow:
1. User clicks an ad or social post → lands on a polished-looking landing page or a “web editor” page.
2. The page pressures the user to download a small helper app, installer, or “codec/extension” to access features, or prompts them to sign in with credentials.
3. The downloaded loader executes (or the user pastes credentials), and the chain moves to payload delivery, often a HVNC/remote-control implant and/or infostealer plugin.
From loader to infostealer, what attackers do next
Once the loader executes, the campaign often follows an operational chain designed to steal data and maintain remote access:
Stage: HVNC / Remote Control, The loader may deploy a remote-control (HVNC) implant to give the attacker interactive access to the desktop. HVNCs let operators view and interact with the victim’s session stealthily, often using stolen credentials or in-memory techniques to evade detection.
Stage: Plugins / Info‑stealers, Plugins or modules are dropped that focus specifically on credential theft and data harvesting: browser passwords, cookies, local password managers, session tokens, crypto wallets, saved RDP credentials, and files in common user folders (Desktop, Downloads).
Data staging & exfiltration, Harvested data is compressed, encrypted, and sent to C2 servers or cloud storage under attacker control. Because the pipeline involves multiple moving parts (loaders → HVNC → plugins → C2), defenders can interpose at several choke points if they have a mapped view.
Persistence & lateral movement, Attackers may install persistence mechanisms (scheduled tasks, services, or startup entries) or use stolen credentials to access other internal systems.
The result: credential theft, account takeover, financial fraud, and potential pivot into broader enterprise compromise.
Detection signals & telemetry to hunt for
A mapped infrastructure makes hunting clearer. Look for these signals across endpoint, network, and identity telemetry:
Endpoint signals
Execution of unknown installers from browser download folders or temporary directories (e.g., Downloads, %TEMP%).
Processes allocating and writing large memory regions (e.g., suspicious VirtualAlloc + WriteFile call patterns).
Creation of suspicious services, scheduled tasks, or new persistence entries.
Unusual parent/child process relationships, notably browsers launching unsigned installers or spawn-chains that terminate user-facing windows quickly.
Network signals
Outbound HTTP/S connections to the C2 IPs and domains listed in the IOC table, especially to uncommon ports or repeated POSTs with small encrypted blobs.
Connections to the fake domain list or social landing pages from multiple internal hosts in short periods (indicates successful lure spread).
Unexpected uploads to cloud storage providers shortly after a suspicious process executes.
Identity & logs
Multiple failed or abnormal authentication attempts using harvested credentials.
New remote sessions from unfamiliar IPs linked to legitimate user accounts.
Behavioral indicators
HVNC-like behavior: unexpected screen capture and remote input patterns (mouse/keyboard emulation), or unusual interactive sessions in RDP/VNC logs.
Rapid file reads from browser profile folders, wallet directories, or PST/OLM mail files.
Mitigations, practical, prioritized steps
1. Block and quarantine the provided IOCs in EDR/AV and proxy filters (IOC table below).
2. Harden download and execution paths: block execution from common staging folders; require User Account Control (UAC) approval and enforce application allowlisting.
3. Enforce MFA and block legacy auth: reduce value of stolen credentials; enforce conditional access policies for sensitive apps.
4. Monitor for HVNC behaviors: detect screen-capture APIs, remote input patterns, and interactive beacons to C2.
5. Protect sensitive stores: enable browser protections (master password, credential vaults), limit credential persistence, and segment systems holding high-value assets.
6. Incident readiness: image infected hosts, collect memory and network captures, and rotate exposed credentials immediately.
7. Takedown & reporting: escalate fake domains and fraudulent social pages to hosting providers and platform abuse teams, providing timestamps and sample hashes.
Compact IOC Table, block these immediately
Stage 1, Loaders (SHA‑256)
F5B31BD394E0A3ADB6BD175207B8C3CCC51850C8F2CEE1149A8421736168E13
F89298933FED52511BB78F8F377979190E37367D72CCF4F3B81374A70362CC42
BEEEA592251A0A205B3BDB34802BD2F4F5181EE38226A05EC468A86BE44E9508
732AA8ED8CA9A12F4BFC29A693EC3EBA74ED1B2D00DE4296180D91B86D09747B
7035B5BA24146DB537EEDB1F05E6CAD1775F9F5E81306F72422C03B288F75448
Stage 2, PureHVNC (SHA‑256)
B33E162A78B7B8E7DBBAB5D1572D63814077FA524067CE79C37F52441B8BD384
0C9228983FBD928AC94C057A00D744D6BE4BD4C1B39D1465B7D955B7D35BF496
839371CD5A5D66828AC9524182769371DEDE9606826AD7C22C3BB18FB2EE91CB
9DAB2BADFDAE86963B2F13CE8942FE78DD66EC497F8D82DD40C0CB5BEC4FB2A7
CEE3F98B5F175219D025A92EDDEC4FD8BCAAE31E6AD99321AE7C00B822063FC3
Plugins (SHA‑256)
1E66EBAEF295C2A32245162979D167CEBAD1FECE51B7CDB6A6C3A1D705BEFA6B
Fake sites & social pages (domains / URLs)
klingaimedia[.]comklingaistudio[.]comklingaieditor[.]comkingaimediapro[.]comkingaivideotext[.]comhttps://www.facebook[.]com/61574724896485/https://www.facebook[.]com/61574162357787/https://www.facebook[.]com/people/KLING-AI/61574316153107/
C2 IPs
185.149.232[.]197185.149.232[.]221147.135.244[.]43
How our service helps
Visual infrastructure map showing ad networks, landing pages, loader clusters, HVNC implants, plugin staging points and C2, prioritized by risk and recurrence.
Exportable blocklists (CSV, STIX, vendor formats) so your team can instantly push indicators to EDR, firewalls, and proxies.
Hunt playbooks tuned for the signature behaviors described above (memory allocations, screen capture, credential harvesting paths).
Takedown support. We assemble evidence packages to report fake domains and social pages to providers and platform abuse teams.
Final note
Fake AI malvertising is effective because it combines slick social engineering with modular malware chains. When the end goal is infostealing, the downstream impact (credential compromise, financial theft, lateral movement) can be severe. Mapping the full infrastructure, ad → loader → HVNC → plugins → C2, gives you multiple choke points to interdict and reduces the attacker’s window for exfiltration.



