Attackers Intercept AI Prompts via Fake Jev AI Stores
Key Takeaways Soon after the launch of the Jev AI model, fake online storefronts emerged, impersonating the official service. These fraudulent sites act as intermediaries, routing user prompts...
Key Takeaways
- Soon after the launch of the Jev AI model, fake online storefronts emerged, impersonating the official service.
- These fraudulent sites act as intermediaries, routing user prompts through third-party servers before reaching the legitimate Jev API.
- Users engaging with these fake stores risk exposing sensitive prompt data to unknown entities and paying significantly inflated prices, up to 11.5 times the official rate.
- The campaign highlights a growing trend of AI brand impersonation, with attackers quickly leveraging new model releases to deceive users.
- No specific malware infection or direct theft of prompts has been confirmed, but the risks of data exposure and financial exploitation are substantial.
Fake Jev AI Stores Intercept Prompts, Inflate Costs
In a rapid response to the debut of Jev, an artificial intelligence model designed to deliver decisive outputs rather than textual responses, a series of fraudulent online storefronts have appeared. These deceptive sites offer access to the Jev service but surreptitiously insert an unauthorized third-party operator between the user and the official API. This arrangement means that all user prompts, and any embedded information, are first transmitted through an external server not controlled by the official Jev developer, as detailed in a report by Eye Security.
Table Of Content
These lookalike portals have successfully infiltrated search engine results for the new AI model. They feature comprehensive interfaces, including “playgrounds,” documentation, pricing structures, and checkout screens, mirroring the legitimate service. Alarmingly, some of these fraudulent sites have even outranked the official Jev website for relevant search queries. This tactic echoes previous AI brand impersonation schemes that capitalized on established or emerging names to cultivate user trust. Researchers Dion Fieret and Lucas Hop from Eye Security were instrumental in identifying these storefronts and mapping their illicit resale mechanisms.
Eye Security said in a report, which was shared with Cyber Security News (CSN), that users could face charges up to 11.5 times the official subscription cost, all while their sensitive prompts traverse servers outside their control. The report did not identify any direct malware infections or confirm the theft of prompts. However, the immediate concerns revolve around the deceptive presentation, exorbitant pricing, and the inherent uncertainty regarding who might access or retain user data.
This situation becomes particularly critical when organizations submit proprietary business information, believing they are engaging directly with the AI model’s legitimate developer. The potential for exposure of sensitive corporate data through these unauthorized intermediaries poses a significant security and privacy risk.
The Mechanics of Deception: How Fake Jev AI Stores Operate
The Jev AI model was officially launched on September 15, 2026. Within a mere three days, two identical domains were registered, approximately 11 hours apart and through distinct registrars, initiating the impersonation campaign. Eye Security’s research revealed that search engine queries for Jev could redirect users to these unauthorized storefronts instead of the legitimate developer’s website. This tactic is consistent with search result poisoning attacks, a known vulnerability exploited in campaigns targeting other AI tools.
These deceptive sites do not appear to offer a counterfeit AI model. Instead, they function as proxies, forwarding user requests to the genuine Jev API while imposing their own inflated charges for access. One of the sites includes terms of service that acknowledge the routing of requests to an upstream model. However, users would need to scrutinize these terms carefully to fully comprehend the operational arrangement. Disclaimers regarding their unaffiliated status are typically relegated to footers or legal pages, conspicuously absent from the checkout process, where users are most likely to make purchasing decisions.
The financial disparity is substantial. According to researchers, the official cost for Jev access is $0.042 per million input tokens. In stark contrast, monthly plans offered by two of the reseller sites ranged from $0.247 to $0.483 per million tokens, representing an approximate six to 11.5-fold increase. While annual billing might reduce one site’s rate, it necessitates a significant upfront payment. The privacy implications are even more difficult to quantify. Eye Security researchers traced one storefront’s requests, observing them route through an application hosted on Railway behind Cloudflare before ultimately reaching the official API. They were unable to ascertain who maintained logs of these transactions, and no service agreement covering this data path was identified. Such concerns regarding the exposure of AI conversation data underscore the critical need to meticulously examine the journey of sensitive prompts.
Reused Templates and the Proliferation of Clones
One of the fake Jev storefronts was identified as part of a larger network comprising six sites that utilized identical underlying code across various AI offerings, including music and video generation. The scripts for this particular Jev clone still contained billing rules originally designed for video generation services. The researchers concluded that the operators were recycling a common storefront template, simply rebranding it whenever a new AI model gained significant traction. Six distinct versions of this template appeared within an 18-day period.
These interconnected sites shared uniform monthly pricing tiers of $29, $49, and $98, frequently accompanied by promotional welcome credits and daily rewards. A recurring countdown timer for “annual savings” reset daily, creating a perpetual sense of urgency for potential customers. Interestingly, some checkout pages indicated that payments were not yet available. The research team also observed changes to legal policy dates during their investigation. Certificate records indicated a surge in new domain registrations containing the “Jev” name in the eight days following the model’s launch, with approximately 670 new domains, roughly double the typical background rate. It is important to note that this count does not exclusively represent malicious sites; some related pages offered free information, others were merely listed for sale, and many remained blank.
Nevertheless, the rapid proliferation of these domains, coupled with the observed overlap with known fake AI tool websites, illustrates the speed and ease with which new AI launches can attract impersonators. Researchers strongly advise users to obtain access links directly from the developer’s official announcements or documentation, rather than relying on search engine rankings. Prospective buyers should meticulously compare per-token pricing, scrutinize domain registration and certificate dates, identify the company explicitly named in the terms of service, and inquire about data handling practices. For production environments, it is imperative to verify that AI access is either direct or routed through a trusted gateway whose data handling policies are explicitly accepted by the organization.
What You Should Do
- Verify Sources Directly: Always obtain links to AI services from official developer websites, announcements, or trusted documentation. Avoid clicking on links from search engine results, advertisements, or unofficial forums.
- Scrutinize Domain Names: Carefully examine the URL of any AI service you intend to use. Look for subtle misspellings, unusual top-level domains (TLDs), or additional characters that differentiate it from the legitimate site.
- Compare Pricing: Cross-reference the pricing displayed on a service portal with the official pricing published by the AI model’s developer. Be wary of significantly higher or unusually low costs.
- Review Terms of Service and Privacy Policies: Read the legal documents thoroughly. Look for clear statements about data handling, third-party involvement, and the identity of the company providing the service. Ensure they explicitly state how your prompts and data will be used, stored, and protected.
- Check for Red Flags: Be suspicious of aggressive sales tactics, countdown timers that reset daily, or inconsistencies in branding, language, or functionality.
- Use Threat Intelligence: Consult lists of known malicious domains (like the IoCs provided below) before interacting with new AI services.
- For Enterprise Use: Implement strict policies requiring direct access to AI APIs or through vetted, approved gateways with clear data governance agreements. Conduct due diligence on any third-party intermediary involved in AI service delivery.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | jev-ai[.]pro |
Jev reseller; shares code with other AI storefronts |
| Domain | jevtypesafeai[.]com |
Jev reseller; routes prompts through a third-party app |
| Domain | jev-agent[.]org |
Jev reseller listed by researchers |
| Domain | jev-agent[.]com |
Jev reseller listed by researchers |
| Domain | jevapi[.]pro |
Jev reseller listed by researchers |
| Domain | jevmodel[.]org |
Jev reseller listed by researchers |
| Domain | jevai[.]site |
Jev reseller listed by researchers |
| Domain | lyria35[.]pro |
Other storefront using the shared code |
| Domain | h3maxturbo[.]pro |
Other storefront using the shared code |
| Domain | faceless-reels[.]pro |
Other storefront using the shared code |
| Domain | taomateh3[.]pro
| Other storefront using the shared code |
| Domain | laya-ai[.]pro |
Other storefront using the shared code |
| Domain | jevai[.]ai |
Jev-related domain observed in certificate records; misuse not established |
| Domain | jevai[.]io |
Jev-related domain also reported as listed for sale |
| Domain | jevai[.]co |
Jev-related domain observed in certificate records; misuse not established |
| Domain | jevai[.]cc |
Jev-related domain observed in certificate records; misuse not established |
| Domain | jevai[.]vip |
Jev-related domain observed in certificate records; misuse not established |
| Domain | jevai[.]xyz |
Jev-related domain observed in certificate records; misuse not established |
| Domain | jevai[.]me |
Jev-related domain observed in certificate records; misuse not established |
| Domain | jevapi[.]io |
Jev-related registered name; misuse not established |
| Domain | jevgateway[.]com |
Jev-related registered name; misuse not established |
| Domain | jevjudge[.]ai |
Jev-related registered name; misuse not established |
| Domain | jevplayground[.]com |
Described by researchers as a free playground, not a confirmed harmful site |
| Domain | jevultrafast[.]com |
Jev-related registered name; misuse not established |
| Domain | jevsystem[.]one |
Jev-related registered name; misuse not established |
| Domain | jevharnessrouter[.]com |
Jev-related registered name; misuse not established |
| Domain | typesafeai[.]app |
Brand-related registered name; misuse not established |
| Domain | typesafe[.]pro |
Describes itself as an independent access gateway |
| Domain | typesafeapi[.]com |
Brand-related registered name; misuse not established |
| Domain | typesafeintelligence[.]com |
Brand-related registered name; misuse not established |
| Domain | jevai[.]co[.]uk |
Jev-related domain reported as listed for sale |
| Domain | jevhub[.]com |
Jev-related domain reported as listed for sale |
| Domain | typesafejev[.]com |
Brand-related domain reported as listed for sale |
| Domain | jev[.]pro |
Described by researchers as a field guide, not a confirmed harmful site |
| Domain | typesafe[.]ai |
Official vendor domain; benign reference, not a malicious indicator |
| Domain | console[.]typesafe[.]ai |
Official dashboard; benign reference, not a malicious indicator |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.