Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Microsoft exposes DNS-based ClickFix attack using Nslookup to stage malware

The computer science exodus (and where are the students going?)

As the venture capital landscape changes, this executive focuses on overlooked founders

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Fake AI tool used to spread noodle malware targeting 62,000+ via Facebook lure
Identity

Fake AI tool used to spread noodle malware targeting 62,000+ via Facebook lure

userBy userMay 12, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 12, 2025Ravi LakshmananMalware/Artificial Intelligence

Fake AI tools used to spread malware

Threat actors are observed as lures to leverage fake artificial intelligence (AI)-powered tools to seduce users to download information steeler malware called nude lofils.

“Instead of relying on traditional phishing and cracked software sites, they build compelling, AI-themed platforms, which are often promoted through legitimately-looking Facebook groups and virus social media campaigns.”

The posts shared on these pages are known to attract over 62,000 views in a single post, indicating that users looking for AI tools for video and image editing are the targets of this campaign. Fake social media pages identified include Luma Dreammachine AL, Luma Dreammachine, and Gratistuslibros.

Users who land on social media posts are encouraged to click on links that promote AI-powered content creation services, such as videos, logos, images, and even websites. One of the fake websites is spoofing Capcut AI and offers users an “all-in-one video editor with new AI capabilities.”

Cybersecurity

When an unsuspecting user uploads an image or video prompt to these sites, the expected AI will be asked to download the generated content, and at that point a malicious zip archive (“videodreamai.zip”) will be downloaded instead.

Residing in the file is a deceptive file named “Video dream machineai.mp4.exe” which kicks off the infection chain by launching a legitimate binary associated with Bytedance’s video editor (“Capcut.exe”). This C++-based executable is used to run a .NET-based loader named CapCutloader that will eventually load the Python payload (“srchost.exe”) from a remote server.

Python binaries pave the way for the deployment of noodle sturlers with the ability to harvest browser credentials, cryptocurrency wallet information, and other sensitive data. Selected instances bundled steelers with remote access trojans like Xworm for colonization access to infected hosts.

Fake AI tools used to spread malware

The noodle developers are rated as Vietnamese origins, and they claim to be “Vietnamese passionate malware developers.” The account was created on March 16th, 2025. It is worth pointing out that Southeast Asian nations have a thriving cybercrime ecosystem with a history of distributing various steeler malware families targeted at Facebook.

Bad actors weaponizing public interest in AI technology for their interests is not a new phenomenon. In 2023, Meta said that since March 2023, it had abolished the sharing of more than 1,000 malicious URLs across services that have been found to utilize Openai’s ChatGPT as a lure to propagate around 10 malware families.

Cybersecurity

As Cyfirma detailed another new .NET-based steeler malware family codename PupkinStealer, disclosures can steal a wide range of data from compromised Windows systems and extend it to attacker-controlled telegram bots.

“Because of the lack of specific anti-analytical defenses or persistent mechanisms, PupkinStealer relies on simple executions and modest behavior to avoid detection during its operation,” the cybersecurity company said. “PupkinStealer illustrates a simple and effective form of simple, effective malware that leverages the behavior of a common system and the widely used platform to extend sensitive information, leveraging the widely used platform.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleKurdish PKK could dissolve and end decades of conflict in Türkiye | News
Next Article Precision agriculture ecosystems are changing the changes in agriculture around the world
user
  • Website

Related Posts

Microsoft exposes DNS-based ClickFix attack using Nslookup to stage malware

February 15, 2026

Google collaborates with Russian actor suspect in failed malware attack on Ukrainian organization

February 13, 2026

Google connects China, Iran, Russia, and North Korea to coordinate defense sector cyber operations

February 13, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Microsoft exposes DNS-based ClickFix attack using Nslookup to stage malware

The computer science exodus (and where are the students going?)

As the venture capital landscape changes, this executive focuses on overlooked founders

Hollywood isn’t happy with new Seedance 2.0 video generator

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.