We review vendors based on rigorous testing and research but also take into account your feedback and our affiliate commission with providers. Some providers are owned by our parent company.
Learn more
vpnMentor was established in 2014 to review VPN services and cover privacy-related stories. Today, our team of hundreds of cybersecurity researchers, writers, and editors continues to help readers fight for their online freedom in partnership with Kape Technologies PLC, which also owns the following products: ExpressVPN, CyberGhost, and Private Internet Access which may be ranked and reviewed on this website. The reviews published on vpnMentor are believed to be accurate as of the date of each article, and written according to our strict reviewing standards that prioritize professional and honest examination of the reviewer, taking into account the technical capabilities and qualities of the product together with its commercial value for users. The rankings and reviews we publish may also take into consideration the common ownership mentioned above, and affiliate commissions we earn for purchases through links on our website. We do not review all VPN providers and information is believed to be accurate as of the date of each article.
Advertising Disclosure

vpnMentor was established in 2014 to review VPN services and cover privacy-related stories. Today, our team of hundreds of cybersecurity researchers, writers, and editors continues to help readers fight for their online freedom in partnership with Kape Technologies PLC, which also owns the following products: ExpressVPN, CyberGhost, and Private Internet Access which may be ranked and reviewed on this website. The reviews published on vpnMentor are believed to be accurate as of the date of each article, and written according to our strict reviewing standards that prioritize professional and honest examination of the reviewer, taking into account the technical capabilities and qualities of the product together with its commercial value for users. The rankings and reviews we publish may also take into consideration the common ownership mentioned above, and affiliate commissions we earn for purchases through links on our website. We do not review all VPN providers and information is believed to be accurate as of the date of each article.

Bing AI Chat Responses Hijacked by Malvertising

Bing AI Chat Responses Hijacked by Malvertising
Keira Waddell Published on 4th October 2023 Former Senior Writer

Malicious advertisements, known as malvertising, have made their way into Microsoft’s Bing Chat AI-powered search engine. Responses from the chatbot may include links to deceptive domains that effectively trick the user into downloading malware.

Microsoft introduced Bing Chat, which is powered by OpenAI's GPT-4 engine, in February 2023. However, the integration of ads into Bing Chat in March has opened the door to malvertisers.

The method behind malvertising is relatively straightforward but highly effective. Hackers strive to deceive ad networks into displaying seemingly legitimate ads that harbor malicious payloads. These deceptive ads often masquerade as software downloads, streaming services, or cryptocurrency-related tools to lure unsuspecting users.

Traditionally, malvertising has plagued mainstream search engines like Google and Bing despite efforts by these tech giants to maintain the integrity of their search results. However, the emergence of Bing Chat, with its AI-driven responses, has marked a shift in the landscape.

When Malwarebytes researchers asked Bing Chat where they could download a program called Advanced IP Scanner, they received a link that redirected them to a site with a deceptive domain, "advenced-ip-scanner[.]com." This subtle alteration (an “e” instead of an “a”), known as typosquatting, could easily go unnoticed by unsuspecting users.

The fake site was designed to mirror the official Advanced IP Scanner page, and encourages users to download the installer. However, as you’d expect, this installer contains a malicious payload.

While Bing Chat offers a unique search experience, it remains susceptible to the same deceptive ads found in traditional Bing queries. Users should always exercise caution when encountering ads in AI-powered chatbots and conventional search results. Scrutinizing ads and double-checking web addresses are essential tactics to avoid falling victim to malicious advertising.

About the Author

Keira was a senior writer at vpnMentor. She is an experienced cybersecurity and tech writer dedicated to providing comprehensive insights on VPNs, online privacy, and internet censorship.

Please, comment on how to improve this article. Your feedback matters!

Leave a comment

Sorry, links are not allowed in this field!

Name should contain at least 3 letters

The field content should not exceed 80 letters

Sorry, links are not allowed in this field!

Please enter a valid email address