Fake AI Subscription Sites Use Cheap Toolkit to Sell $2,000 Annual Plans
What Happened – Malwarebytes identified more than 100 look‑alike subscription sites that sell AI tools (e.g., “GPT‑6 Astra”, “PixAI”, “OpenCut”) for up to $2,000 a year. All sites share the same underlying web‑kit, identical developer email addresses, and a polished Google‑sign‑in flow, but none provide verifiable ownership or independent reviews.
Why It Matters for Trust & Control Assurance
- The campaign exploits the assumption that a TLS‑protected site and a Google login automatically imply legitimacy – a gap that a continuous third‑party risk program is designed to surface and document.
- Without systematic vendor vetting and evidence collection, organizations may inadvertently spend on fraudulent services, eroding financial controls and audit defensibility.
Who Is Affected – SaaS providers, AI‑focused startups, enterprise procurement teams, and any end‑users who purchase cloud‑based AI subscriptions.
Recommended Actions
- Add the identified domains to your deny‑list and flag any procurement request that references them.
- Enforce a vendor‑onboarding workflow that requires independent verification (e.g., business registration, third‑party attestations, proof of product demo) before any subscription is approved.
- Deploy continuous monitoring of external web assets for brand‑impersonation patterns and collect evidence for audit trails.
Technical Notes – The fraudulent sites use valid TLS certificates, authentic‑looking Google OAuth screens, and identical HTML/JS bundles. No malware is delivered, but the payment flow is real, and some sites request uploads of documents or media for processing. Source: https://www.malwarebytes.com/blog/threat-intel/2026/09/the-fake-sites-using-a-cheap-toolkit-to-sell-2000-ai-subscriptions