Fake AI Tools Spread Noodlophile Malware, Targeting Crypto Wallets and Sensitive Data

4 Sources

A new malware campaign exploits the popularity of AI tools to spread Noodlophile, an information stealer that targets browser credentials, cryptocurrency wallets, and other sensitive data.

News article

Noodlophile Malware Exploits AI Hype

A sophisticated malware campaign is leveraging the growing interest in AI-powered tools to spread a dangerous information stealer called Noodlophile. Cybersecurity researchers at Morphisec have uncovered a scheme where threat actors create convincing AI-themed platforms to lure unsuspecting users into downloading malicious software 1.

Social Media Spread and Targeting

The attackers are using legitimate-looking Facebook groups and viral social media campaigns to advertise their fake AI tools. Posts on these platforms have garnered significant attention, with a single post attracting over 62,000 views. The campaign specifically targets users seeking AI tools for video and image editing 1.

Infection Mechanism

When users visit these fraudulent websites, they are prompted to upload images or videos for AI-generated content. Instead of receiving the promised AI-created material, victims unknowingly download a malicious ZIP archive named "VideoDreamAI.zip". This archive contains an executable file disguised as a video, which initiates a complex infection chain 2.

Noodlophile Capabilities

Once deployed, Noodlophile exhibits powerful data-stealing capabilities:

  1. Harvests browser credentials from major browsers including Chrome, Edge, Brave, and Opera
  2. Extracts cryptocurrency wallet information
  3. Gathers other sensitive data from the infected system 3

In some instances, the malware is bundled with a remote access trojan called XWorm, granting attackers deeper control over the compromised devices 2.

Data Exfiltration and Command Structure

The stolen information is transmitted in real-time to the attackers using a Telegram bot, which also serves as a command-and-control server for the malware. This setup allows hackers immediate access to the exfiltrated data 4.

Origin and Broader Context

Researchers suspect that Noodlophile originates from Vietnam, based on a GitHub profile claiming to be a "passionate Malware Developer from Vietnam." This aligns with observations of a thriving cybercrime ecosystem in Southeast Asia, particularly focused on distributing stealer malware through Facebook 1.

Protective Measures

To safeguard against such threats, cybersecurity experts recommend:

  1. Using caution when downloading files from unfamiliar websites
  2. Verifying file extensions before executing downloads
  3. Enabling file extension visibility in Windows
  4. Utilizing malware scanners to check downloads before opening
  5. Keeping operating systems and antivirus software up-to-date 3 4

This campaign underscores the evolving tactics of cybercriminals, who are quick to exploit public interest in emerging technologies like AI to distribute malware and compromise user security.

Explore today's top stories

Google Unveils AI-Powered Pixel 10 Smartphones with Advanced Gemini Features

Google launches its new Pixel 10 smartphone series, showcasing advanced AI capabilities powered by Gemini, aiming to challenge competitors in the premium handset market.

Bloomberg Business logoThe Register logoReuters logo

20 Sources

Technology

29 mins ago

Google Unveils AI-Powered Pixel 10 Smartphones with

Google Unveils AI-Powered Pixel 10 Series: A New Era of Smartphone Intelligence

Google's Pixel 10 series introduces groundbreaking AI features, including Magic Cue, Camera Coach, and Voice Translate, powered by the new Tensor G5 chip and Gemini Nano model.

TechCrunch logoZDNet logoengadget logo

12 Sources

Technology

46 mins ago

Google Unveils AI-Powered Pixel 10 Series: A New Era of

NASA and IBM Unveil Surya: An AI Model to Predict Solar Flares and Space Weather

NASA and IBM have developed Surya, an open-source AI model that can predict solar flares and space weather with improved accuracy, potentially helping to protect Earth's infrastructure from solar storm damage.

New Scientist logoengadget logoGizmodo logo

6 Sources

Technology

8 hrs ago

NASA and IBM Unveil Surya: An AI Model to Predict Solar

Google Unveils Pixel Watch 4: A Leap Forward in AI-Powered Wearables

Google's latest smartwatch, the Pixel Watch 4, introduces significant upgrades including a curved display, enhanced AI features, and improved health tracking capabilities.

TechCrunch logoCNET logoZDNet logo

17 Sources

Technology

27 mins ago

Google Unveils Pixel Watch 4: A Leap Forward in AI-Powered

FieldAI Secures $405M Funding to Revolutionize Robot Intelligence with Physics-Based AI Models

FieldAI, a robotics startup, has raised $405 million to develop "foundational embodied AI models" for various robot types. The company's innovative approach integrates physics principles into AI, enabling safer and more adaptable robot operations across diverse environments.

TechCrunch logoReuters logoGeekWire logo

7 Sources

Technology

36 mins ago

FieldAI Secures $405M Funding to Revolutionize Robot
TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo