4 Sources
[1]
Fake AI Tools Used to Spread Noodlophile Malware, Targeting 62,000+ via Facebook Lures
Threat actors have been observed leveraging fake artificial intelligence (AI)-powered tools as a lure to entice users into downloading an information stealer malware dubbed Noodlophile. "Instead of relying on traditional phishing or cracked software sites, they build convincing AI-themed platforms
[2]
Fake AI Tools Used to Spread Noodlophile Crypto Wallet Stealing Malware - Decrypt
Noodlophile stealer, which researchers suspect originated in Vietnam, can include additional remote access trojans. People are being tricked into downloading fake AI tools as a way to spread the information stealer malware Noodlophile. This malware is able to harvest browser credentials,
[3]
This AI Video Generator Is Spreading Malware
Noodlophile steals account credentials and crypto wallet files. Cyber attackers are capitalizing on user demand for AI-generated content by spreading malware targeted at creators and small businesses in the form of fake AI content services. As Bleeping Computer reports, a new infostealer known as
[4]
Using the Wrong AI Video Generator Could Infect Your PC With Malware
These Are the 6 Ways Scammers Use TikTok to Infect Your Devices With Malware There are plenty of free AI image and video generators out there, but some can be outright dangerous to use. If you end up using the wrong AI video generator, you'll get a side of malware served with it. AI Video
Share
Copy Link
A new malware campaign exploits the popularity of AI tools to spread Noodlophile, an information stealer that targets browser credentials, cryptocurrency wallets, and other sensitive data.

A sophisticated malware campaign is leveraging the growing interest in AI-powered tools to spread a dangerous information stealer called Noodlophile. Cybersecurity researchers at Morphisec have uncovered a scheme where threat actors create convincing AI-themed platforms to lure unsuspecting users into downloading malicious software
1
.The attackers are using legitimate-looking Facebook groups and viral social media campaigns to advertise their fake AI tools. Posts on these platforms have garnered significant attention, with a single post attracting over 62,000 views. The campaign specifically targets users seeking AI tools for video and image editing
1
.When users visit these fraudulent websites, they are prompted to upload images or videos for AI-generated content. Instead of receiving the promised AI-created material, victims unknowingly download a malicious ZIP archive named "VideoDreamAI.zip". This archive contains an executable file disguised as a video, which initiates a complex infection chain
2
.Once deployed, Noodlophile exhibits powerful data-stealing capabilities:
3
In some instances, the malware is bundled with a remote access trojan called XWorm, granting attackers deeper control over the compromised devices
2
.The stolen information is transmitted in real-time to the attackers using a Telegram bot, which also serves as a command-and-control server for the malware. This setup allows hackers immediate access to the exfiltrated data
4
.Related Stories
Researchers suspect that Noodlophile originates from Vietnam, based on a GitHub profile claiming to be a "passionate Malware Developer from Vietnam." This aligns with observations of a thriving cybercrime ecosystem in Southeast Asia, particularly focused on distributing stealer malware through Facebook
1
.To safeguard against such threats, cybersecurity experts recommend:
3
4
This campaign underscores the evolving tactics of cybercriminals, who are quick to exploit public interest in emerging technologies like AI to distribute malware and compromise user security.
Summarized by
Navi
[1]
[3]