Researchers found hundreds of paid ads running across Meta platforms that promoted “nudification”/face‑swap apps and included abusive sexual content involving minors, including some using real children’s photos pulled from the web. The ads used manipulative marketing text (for example, claiming there are “no restriction” on what can be done with a child’s image) and drove clicks to app-store downloads. The report highlights how deceptive ad copy and seemingly innocent images can be used to funnel users to harmful tools.
Key findings
- Researchers reported “more than 250 additional ads containing CSAM” running since the start of August, despite prior removals.
- Ads followed a repeatable lure pattern: an “innocuous picture” plus text implying unlimited manipulation, then a click-through to download AI face-swap/video apps from official app stores.
- Some abusive ads used images of identifiable real children sourced from the web (including public influencer photos and stock-photo sites), not only AI-generated images.
- The ads ran across multiple Meta surfaces (Facebook, Instagram, Messenger, Threads, and Meta’s ad network) and were shown to tens of thousands of accounts across several countries.
Who’s being targeted
- Commonly targeted roles: All employees, Marketing, Communications, IT (endpoint/app control), Trust & Safety / Content Moderation, HR (employee safety reporting channels).
- Affected industries: Social media platforms, Online advertising, Consumer internet / app marketplaces.
- Attack channels: website.
- Impersonated: An AI face-swapping / video app advertiser.
Awareness takeaways
- Treat “curiosity hook” ads as risky, don’t click or install apps promoted via sensational teaser text.
- Assume official-looking platforms and app stores can still be used as distribution channels for harmful or policy-violating content; use allowlists and approved-software processes at work.
- If you see abusive or clearly policy-violating ads, report them quickly through both the platform’s tools and internal escalation channels; delays can increase harm.
Red flags to watch for
- Manipulative/sexualized teaser language designed to drive curiosity clicks
- Claims implying there are “no restriction” on using someone’s image
- Ad redirects to download an app based on shock/curiosity rather than a legitimate business need
Read the video transcript
You’re scrolling Instagram and see a normal photo of a teen with the text: “not just a photo… there are no restriction.” Researchers found hundreds of these paid Meta ads. They use innocent pictures of preteen or teenage girls, then push you to download AI face-swap or video apps from Apple or Google’s app stores. Here’s the twist: some of these ads used real kids’ photos pulled from the web and bragged, “This is the AI that men actually use.” If an ad’s only hook is shock or sexualized curiosity, that’s your red flag. At work, if you see a “not just a photo” style ad pushing an AI app, don’t click it, screenshot it and report it through the platform and our internal security channel.