Cybercriminals are abusing interest in generative AI to trick users into downloading malware. In a newly documented incident, a file posing as a Google Gemini installer delivered the Vidar information stealer, putting saved browser passwords and other sensitive data at risk.
The attack did not begin with a phishing email. Instead, it relied on a normal-looking software search and download path, showing how criminals can turn routine searches for AI tools into a route for credential theft.
The tactic mirrors recent campaigns that used fake AI installers and search manipulation to distribute password-stealing malware. Hackers using fake Claude pages have similarly shown how convincing AI-themed downloads can mislead users.
Analysts from Darktrace identified the activity in July 2026 within a customer environment in the Europe, Middle East and Africa region.
Darktrace said in a report shared with Cyber Security News (CSN) that they linked the suspicious executable to Vidar after detecting unusual process behavior, outbound connections, and signs that browser credentials were being collected.
The case highlights a wider shift in malware delivery. Attackers are increasingly placing harmful files behind familiar names, trusted cloud services, and popular AI brands, betting that users will lower their guard when a download appears connected to a well-known platform.
The infection chain began when a user launched a file named Download_Google_Gemini_For_Windows.exe from the Downloads folder.
Darktrace found that searches for the filename led to a Google Colab page containing a download prompt, giving the campaign an appearance of legitimacy.
Google Colab is commonly used by developers and researchers, which made it a useful staging point for the lure.
The page redirected visitors to a second website posing as a “Windows Software Hub,” where the fake Gemini installer was offered for download.
The investigation did not recover HTTP or file-download telemetry that conclusively established the initial download source.
However, encrypted sessions with Google Colab occurred immediately before the executable launched, strongly suggesting that the user interacted with the hosted resource before reaching the secondary download site.
At the time researchers reviewed the activity, the Colab page remained active and offered a ZIP archive containing the malicious binary.
It also included a README file that told users to run the program with administrator rights and add it to antivirus exception lists, a clear warning sign that the instructions were designed to weaken normal defenses.
Once executed, the program was identified as a newer Go-compiled Vidar variant. It communicated with infrastructure associated with Telegram and connected to suspicious external systems over port 443. This behavior helped investigators connect the fake installer to the wider credential-stealing operation.
The campaign shows why trusted hosting alone cannot validate a download. Similar risks have emerged as attackers weaponize AI interest through cloned repositories, misleading setup guides, and harmful archives.
A recent fake AI tool campaign also demonstrated how attackers can exploit trusted-looking developer resources to distribute stealers.
Vidar is built to collect valuable information from infected devices. In this incident, later endpoint alerts confirmed activity consistent with theft of browser credentials and other sensitive data.
Saved passwords, browser-based session data, and related information can give attackers access to email, business services, or personal accounts without needing to guess a password.
The affected device contacted an external IP address shortly after the fake installer ran. Researchers also identified a related IP through SSL certificate analysis, along with a command-and-control domain connected to the activity.
Darktrace contained the incident by blocking communications with suspicious infrastructure and quarantining the compromised endpoint.
The response was triggered by behavior that did not match the device’s normal activity, rather than by the apparent legitimacy of the installer or the hosting platform.
For organizations, the practical lesson is to treat AI software downloads with the same caution applied to any other application.
Users should obtain Gemini-related tools only from verified official sources, avoid search-result downloads that lead through unfamiliar pages, and never follow instructions to disable or exclude antivirus protection.
Security teams should also investigate unusual browser credential access, new executables launched from Downloads folders, and rare encrypted connections from recently installed programs.
These controls are especially important as SEO poisoning Gemini campaigns continue to use convincing search results and false installation guidance to target users.
The campaign relied on a fake Gemini installer, trusted-platform abuse, and social engineering to deliver an established information stealer through a more convincing route.
The broader risk is not limited to one malware family: attackers are now treating the demand for AI tools as a dependable lure for credential theft.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| File | Download_Google_Gemini_For_Windows.exe | Fake Gemini-themed installer observed during the investigation |
| File | GoogleAppInstaller.exe | Related executable identified through endpoint telemetry |
| IP Address | 91.98.98[.]86 | External destination contacted by the malicious executable |
| IP Address | 91.98.111[.]49 | Related infrastructure identified through SSL certificate pivoting |
| Domain | dtm[.]kijangturbo88[.]top | Command-and-control endpoint identified during malware analysis |
| SHA-256 | 1e13c2c9eac72daf63fd00a9946878949e159ae6ec51b54ec64f942d79d61913 | Malware sample associated with the fake Gemini installer |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…