X Grok malicious-link bypass campaign
Campaign
Summary
Hide ▲
Show ▼
Campaign activity on X is abusing Grok to turn hidden URLs in video-card "From:" metadata into clickable links, a bypass Guardio Labs dubbed "grokking". The operation is being used to spread malicious links to millions of users at a time, with reporting that it is happening hundreds of times a day. The abuse can boost scam, malware, and other shady content by leveraging a trusted assistant reply and the reach of promoted posts.
Related Happenings
ClickFix MacSync social-engineering campaign targeting macOS users
Campaign
H score38
First: 16.03.2026 13:41
Last: 16.03.2026 13:41
Sources 1
About this happening:
ClickFix campaigns continued to blend fake verification pages with command-pasting lures, including a 2025-11-06 wave that used embedded video tutorials, automatic O...
ClickFix MacSync social-engineering campaign targeting macOS users
CampaignAbout this happening: ClickFix campaigns continued to blend fake verification pages with command-pasting lures, including a 2025-11-06 wave that used embedded video tutorials, automatic O...
Perplexity Comet prompt-injection research shows agentic browsers can be trained into phishing traps
Technical Analysis
H score25
First: 11.03.2026 18:38
Last: 11.03.2026 18:38
Sources 1
About this happening:
Perplexity's Comet AI browser is the focus of a technical analysis thread showing how prompt injection and malicious URLs can steer an agentic browser into data...
Perplexity Comet prompt-injection research shows agentic browsers can be trained into phishing traps
Technical AnalysisAbout this happening: Perplexity's Comet AI browser is the focus of a technical analysis thread showing how prompt injection and malicious URLs can steer an agentic browser into data...
AI assistants with web browsing repurposed as covert C2 relays
Technical Analysis
H score45
First: 18.02.2026 17:00
Last: 18.02.2026 17:00
Sources 1
About this happening:
AI assistants with web browsing are now being shown as covert command-and-control relays, letting malware hide commands and stolen data inside routine enterprise traffic. Gr...
AI assistants with web browsing repurposed as covert C2 relays
Technical AnalysisAbout this happening: AI assistants with web browsing are now being shown as covert command-and-control relays, letting malware hide commands and stolen data inside routine enterprise traffic. Gr...
AMOS infostealer delivered through Google ads and poisoned ChatGPT/Grok lures
Malware Activity
H score30
First: 11.12.2025 01:50
Last: 11.12.2025 01:50
Sources 1
About this happening:
The AMOS infostealer is being distributed through Google search ads that steer macOS users into poisoned ChatGPT and Grok conversations, creating a fresh path to c...
AMOS infostealer delivered through Google ads and poisoned ChatGPT/Grok lures
Malware ActivityAbout this happening: The AMOS infostealer is being distributed through Google search ads that steer macOS users into poisoned ChatGPT and Grok conversations, creating a fresh path to c...
X Grokking malvertising campaign
Campaign
H score34
First: 04.09.2025 13:21
Last: 04.09.2025 13:21
Sources 1
About this happening:
Cybercriminals are running a coordinated X malvertising campaign that abuses Grok to surface hidden malicious links and push them into millions of feeds. The opera...
X Grokking malvertising campaign
CampaignAbout this happening: Cybercriminals are running a coordinated X malvertising campaign that abuses Grok to surface hidden malicious links and push them into millions of feeds. The opera...
Timeline
-
04.09.2025 01:01 3 articles · 10mo ago
Threat actors abuse X's Grok AI to surface hidden malicious links
Initial DisclosureThreat actors are abusing X's Grok AI to bypass link-posting restrictions by hiding malicious URLs in the video card's "From:" metadata and then asking Grok to reveal them. Grok returns the full malicious link in clickable format, which boosts credibility and reach on X and can drive users to scams, fake CAPTCHA tests, information-stealing malware, and other malicious payloads.
Show sources
- Threat actors abuse X’s Grok AI to spread malicious links — www.bleepingcomputer.com — 04.09.2025 01:01
- Threat actors abuse X’s Grok AI to spread malicious links — www.bleepingcomputer.com — 04.09.2025 01:01
- Scammers Are Using Grok to Spread Malicious Links on X — www.darkreading.com — 05.09.2025 18:41