BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Cybercriminals Use Grok AI to Bypass X’s Malvertising Protections

Cybercriminals Exploit X’s Grok AI to Bypass Ad Protections and Spread Malware via “Grokking” Technique

  • Cybercriminals are using a new strategy to get around ad protections on X (formerly Twitter) by leveraging its AI assistant, Grok.
  • The method, called “Grokking,” hides malicious links in video ad metadata and prompts the AI to reveal them publicly.
  • Links exposed by Grok lead users to harmful sites, including Malware, fake CAPTCHA scams, and fraudulent ad networks.
  • Research from Guardio Labs found hundreds of accounts repeatedly using this approach until suspension.
  • This organized campaign boosts malicious link exposure through both promoted content and AI-driven responses.

Cybersecurity researchers identified a new technique that allows cybercriminals to bypass ad protections on the social media platform X by taking advantage of its Artificial Intelligence tool, Grok. The approach has led to a rise in the spread of harmful links on the platform, with attackers promoting adult content in ads and hiding the dangerous links in ad metadata fields.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

The technique, known as “Grokking,” was reported by Nati Tal, head of Guardio Labs, and involves posting video ads with bait content.

The malicious links are hidden in the “From:” metadata below the video player, a section not typically scanned by the platform. Attackers then tag Grok in replies to these posts and ask where the video originates, prompting the AI to surface the hidden link in its response.

According to Tal,

“A malicious link that X explicitly prohibits in ads (and should have been blocked entirely!) suddenly appears in a post by the system-trusted Grok account, sitting under a viral promoted thread and spreading straight into millions of feeds and search results!”

The links, as identified by Guardio Labs, redirect users to deceptive ad networks that deliver malware, fake CAPTCHA scams, and other fraudulent content through direct link monetization. The domains involved use a Traffic Distribution System (TDS) which helps redirect users to various harmful sites.

- Advertisement -

Guardio Labs told The Hacker News that they discovered hundreds of accounts utilizing this method, each responsible for posting large numbers of these ads over several days.

“They seem to be posting non-stop for several days until the account gets suspended for violating platform policies,” the company reported, adding that the activity appears highly coordinated.

Researchers also noted that when Grok amplifies these links, it helps boost their visibility in search engine results and improves the domains’ reputations. This method not only spreads the malicious links to X’s wide user base but also helps the attackers sidestep existing protections in promoted advertisements.

Investigations are ongoing as X attempts to address the vulnerabilities and suspend accounts connected to these campaigns. So far, the persistent posting has revealed a broader pattern of organized malicious activity targeting the platform’s ad and AI features.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin Awaits Fed Chair Powell’s Policy Signals

Bitcoin's immediate price direction hinges on Federal Reserve Chair Jerome Powell's latest policy signals.A...

S&P 500 Perpetual Futures Launch on Hyperliquid

S&P Dow Jones Indices has licensed its S&P 500 Index for an onchain perpetual...

Stripe-backed Tempo blockchain launches for AI agents

Tempo, backed by Stripe and Paradigm, officially launched its payments-focused blockchain after months of...

Viv Ford’s “Crypto Castle” YouTube show revisits $250 Bitcoin era

Comedian Viv Ford launches a YouTube sitcom, "The Crypto Castle," set in 2015 San...

Vanity Fair’s “Crypto Believers” Shoot Sparks Mockery

A Vanity Fair photoshoot starring key crypto figures drew widespread criticism for its perceived...

Must Read

Ethereum Hosting: TOP 10 Companies to Buy Hosting With Ethereum

If you are looking for Ethereum Hosting, you've hit the jackpot. In this article, we will present the 10 Best companies to buy hosting...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading