Oct 13, 2025 • ESET WeLiveSecurity
AI-aided malvertising: Exploiting a chatbot to spread scams
Cybercriminals are exploiting X's AI chatbot (Grok) by manipulating it to promote phishing scams through a technique dubbed 'Grokking.' This novel attack...
Executive Summary
Cybercriminals are exploiting X's AI chatbot (Grok) by manipulating it to promote phishing scams through a technique dubbed 'Grokking.' This novel attack vector demonstrates how threat actors are increasingly targeting AI systems as delivery mechanisms for malicious content. The technique involves tricking the AI chatbot into generating phishing links or scam content that appears legitimate. Organizations should implement content filtering and safeguards for AI-generated outputs, educate users about AI-generated content risks, and monitor for AI-facilitated scams. The emergence of 'Grokking' signals an evolving threat landscape where AI systems themselves become attack surfaces for social engineering campaigns.
Summary
Cybercriminals have tricked X’s AI chatbot into promoting phishing scams in a technique that has been nicknamed “Grokking”. Here’s what to know about it.
Published Analysis
Cybercriminals are exploiting X's AI chatbot (Grok) by manipulating it to promote phishing scams through a technique dubbed 'Grokking.' This novel attack vector demonstrates how threat actors are increasingly targeting AI systems as delivery mechanisms for malicious content. The technique involves tricking the AI chatbot into generating phishing links or scam content that appears legitimate. Organizations should implement content filtering and safeguards for AI-generated outputs, educate users about AI-generated content risks, and monitor for AI-facilitated scams. The emergence of 'Grokking' signals an evolving threat landscape where AI systems themselves become attack surfaces for social engineering campaigns. Cybercriminals have tricked X’s AI chatbot into promoting phishing scams in a technique that has been nicknamed “Grokking”. Here’s what to know about it. Cybercriminals have tricked X’s AI chatbot into promoting phishing scams in a technique that has been nicknamed “Grokking”. Here’s what to know about it.