Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Tesla has announced the launch of human-assisted Robotaki in San Francisco, but state regulators say it isn’t

Astronomer winks with “temporary spokesman” Gwyneth Paltrow in the viral infamy

Tesla Vet says “reviewing real products, not mockups” is the key to innovative maintenance

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Fake AI tool used to spread noodle malware targeting 62,000+ via Facebook lure
Identity

Fake AI tool used to spread noodle malware targeting 62,000+ via Facebook lure

userBy userMay 12, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 12, 2025Ravi LakshmananMalware/Artificial Intelligence

Fake AI tools used to spread malware

Threat actors are observed as lures to leverage fake artificial intelligence (AI)-powered tools to seduce users to download information steeler malware called nude lofils.

“Instead of relying on traditional phishing and cracked software sites, they build compelling, AI-themed platforms, which are often promoted through legitimately-looking Facebook groups and virus social media campaigns.”

The posts shared on these pages are known to attract over 62,000 views in a single post, indicating that users looking for AI tools for video and image editing are the targets of this campaign. Fake social media pages identified include Luma Dreammachine AL, Luma Dreammachine, and Gratistuslibros.

Users who land on social media posts are encouraged to click on links that promote AI-powered content creation services, such as videos, logos, images, and even websites. One of the fake websites is spoofing Capcut AI and offers users an “all-in-one video editor with new AI capabilities.”

Cybersecurity

When an unsuspecting user uploads an image or video prompt to these sites, the expected AI will be asked to download the generated content, and at that point a malicious zip archive (“videodreamai.zip”) will be downloaded instead.

Residing in the file is a deceptive file named “Video dream machineai.mp4.exe” which kicks off the infection chain by launching a legitimate binary associated with Bytedance’s video editor (“Capcut.exe”). This C++-based executable is used to run a .NET-based loader named CapCutloader that will eventually load the Python payload (“srchost.exe”) from a remote server.

Python binaries pave the way for the deployment of noodle sturlers with the ability to harvest browser credentials, cryptocurrency wallet information, and other sensitive data. Selected instances bundled steelers with remote access trojans like Xworm for colonization access to infected hosts.

Fake AI tools used to spread malware

The noodle developers are rated as Vietnamese origins, and they claim to be “Vietnamese passionate malware developers.” The account was created on March 16th, 2025. It is worth pointing out that Southeast Asian nations have a thriving cybercrime ecosystem with a history of distributing various steeler malware families targeted at Facebook.

Bad actors weaponizing public interest in AI technology for their interests is not a new phenomenon. In 2023, Meta said that since March 2023, it had abolished the sharing of more than 1,000 malicious URLs across services that have been found to utilize Openai’s ChatGPT as a lure to propagate around 10 malware families.

Cybersecurity

As Cyfirma detailed another new .NET-based steeler malware family codename PupkinStealer, disclosures can steal a wide range of data from compromised Windows systems and extend it to attacker-controlled telegram bots.

“Because of the lack of specific anti-analytical defenses or persistent mechanisms, PupkinStealer relies on simple executions and modest behavior to avoid detection during its operation,” the cybersecurity company said. “PupkinStealer illustrates a simple and effective form of simple, effective malware that leverages the behavior of a common system and the widely used platform to extend sensitive information, leveraging the widely used platform.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleKurdish PKK could dissolve and end decades of conflict in Türkiye | News
Next Article Precision agriculture ecosystems are changing the changes in agriculture around the world
user
  • Website

Related Posts

N. The US sanctions company behind the Korean IT scheme. Arizona woman was jailed to run a laptop farm

July 25, 2025

Patchwork targets Turkish defense companies with spear phishing using malicious LNK files

July 25, 2025

Cyberspy Campaign hits Russian aerospace sector using Eaglet Backdoor

July 25, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Tesla has announced the launch of human-assisted Robotaki in San Francisco, but state regulators say it isn’t

Astronomer winks with “temporary spokesman” Gwyneth Paltrow in the viral infamy

Tesla Vet says “reviewing real products, not mockups” is the key to innovative maintenance

Allianz Life says “majority” of customer personal data stolen in a cyber attack

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Tim Berners-Lee Unveils the “Missing Link”: How the Web’s Architect Is Building AI’s Trusted Future

Dispatch from London Tech Week: Keir Starmer, The Digital Twin Boom, and FySelf’s Game-Changing TwinH

Is ‘Baby Grok’ the Future of Kids’ AI? Elon Musk Launches New Chatbot

Next-Gen Digital Identity: How TwinH and Avatars Are Redefining Creation

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.