A malware campaign is using fake AI-themed websites, impersonating legitimate tools like Luma Dream Machine and CapCut, to distribute a new infostealer called 'Noodlophile'. Attackers lure users via social media to upload images for 'AI processing', then provide a malicious ZIP file instead of the promised media. The malware, which is sometimes bundled with the XWorm remote access trojan, steals browser credentials, cookies, and cryptocurrency wallet data, exfiltrating it via Telegram bots.
A campaign reportedly used fake AI video generation sites to distribute malware under the guise of AI-generated content. Promoted via social media, these sites allegedly tricked users into downloading files containing Noodlophile Stealer, a previously unreported infostealer, and in some cases XWorm. The malware harvested credentials and could enable remote access.
Risk classification
- Primary risk domain: 4 Malicious actors
- Primary risk subdomain: 4.3 Fraud, scams, and targeted manipulation
The incident involves threat actors setting up fake AI platforms and social media pages to scam users into downloading malware under the guise of legitimate AI services.
Additional risk subdomains
- 2.1 Compromise of privacy by obtaining, leaking or correctly inferring sensitive information: The Noodlophile malware deployed via the scam is specifically designed to steal sensitive personal data, including browser credentials, cookies, and crypto wallets.
Causal factors
- Entity: Human
- Intent: Intentional
- Timing: Post-deployment
The incident is a social engineering campaign orchestrated by human threat actors who intentionally exploit the popularity of deployed AI systems to distribute malware.
EU AI Act risk tier
- Risk tier: 4 Minimal or No Risk
Minimal or No Risk: The AI systems being impersonated (Luma Dream Machine and CapCut) are general-purpose image and video generation tools used for entertainment and content creation, which pose minimal or no risk under the EU AI Act.
AI system and alleged parties
- AI system: unspecified AI-powered content creation tool
- AI purpose: Visual Art Generation; Image Generation
- Behaviour type: Tool
- Alleged developer: Unknown developer of Noodlophile Stealer
- Alleged deployer: Unknown developer of Noodlophile Stealer, Unknown actors operating fraudulent AI-themed websites, Unknown actors distributing malware-as-a-service (MaaS)
- Alleged harmed parties: Users whose devices were potentially compromised via remote access trojans (RATs), Targets of credential theft, Small businesses targeted by Noodlophile Stealer, Individuals targeted by Noodlophile Stealer
Harm severity
Highest direct severity in any category: Minor. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.
- Physical: direct Negligible, indirect Negligible
- Infrastructure: direct Negligible, indirect Negligible
- Property: direct Negligible, indirect Negligible
- Financial: direct Negligible, indirect Negligible
- Environmental: direct Negligible, indirect Negligible
- Malicious content: direct Minor, indirect Negligible
- Differential treatment: direct Negligible, indirect Negligible
- Civil rights: direct Negligible, indirect Negligible
- Democracy: direct Negligible, indirect Negligible
- Privacy: direct Minor, indirect Negligible
- Psychological: direct Negligible, indirect Negligible
- Epistemic: direct Minor, indirect Negligible
- Child sexual exploitation and abuse: direct Negligible, indirect Negligible
Malicious content
Reported: Yes, the report describes the creation and distribution of malicious software and fake platforms.
Directly caused: Threat actors created fake AI-themed websites and distributed the Noodlophile malware disguised as video files.
Indirectly caused: N/A
Inferred additional harm: The malware was likely distributed to hundreds of users who downloaded the ZIP files from the fake platforms.
Privacy
Reported: Yes, the report explicitly describes the deployment of malware designed to steal sensitive personal data.
Directly caused: The Noodlophile malware was designed to harvest browser credentials, session cookies, tokens, and cryptocurrency wallet files from infected hosts.
Indirectly caused: N/A
Inferred additional harm: It is highly likely that numerous victims had their private credentials and financial data exfiltrated to the attackers via Telegram bots.
Epistemic
Reported: Yes, the report describes the creation of fake websites and social media pages to deceive users.
Directly caused: Threat actors built convincing fake platforms and social media pages impersonating legitimate AI tools like Luma Dream Machine and CapCut to mislead users.
Indirectly caused: N/A
Inferred additional harm: The campaign contributes to a general erosion of trust in online AI platforms and digital content.
People affected
- Occurrences reported: 1
- People reportedly exposed: 62000
Potential causes
Management
- Lack of Strict Activity Separation: Businesses failed to separate business tasks from personal AI testing.
Technology
- Deceptive Executable Extensions: Exploited Windows disabled file extensions to hide exe as mp4.
- Evasion of Static Scanners: Large binary size and code obfuscation bypassed traditional scanners.
- Memory-Based Payload Execution: Executing malware in-memory to evade traditional disk-based detection.
Data Inputs
- Malicious Prompt Upload Portals: Fake AI sites accepted user files to mimic real AI processing.
- Fake Video Generation Outputs: Delivering malicious ZIP files disguised as AI-generated video outputs.
- Obfuscated Script Inputs: Using division-by-zero lines to break automated AST parsers.
Human Factors
- Exploitation of AI Hype: High public interest in generative AI made users trust fake platforms.
- Disabled File Extensions: Windows users unable to see the true exe extension of the file.
- Trust in Social Media Verification: Verified badges on fake Facebook pages increased perceived legitimacy.
Process and Methods
- Lack of Platform Moderation: Social media platforms failed to quickly remove fake AI advertisements.
- Lack of Download Verification: Users downloading files from unverified third-party websites.
- Inadequate Security Training: Small businesses and freelancers lacked training to spot fake AI lures.
Regulatory Environment
- Weak Cybercrime Enforcement: Thriving regional cybercrime ecosystems operate with minimal enforcement.
Information quality
- Classification confidence: High
- Reason for confidence: The reports from multiple cybersecurity sources provide highly detailed and consistent technical analyses of the malware campaign, its delivery mechanisms, and the specific AI tools being impersonated. There is little ambiguity regarding the facts of the campaign.
- Ambiguities identified: The exact number of successfully compromised victims and the total financial value of stolen assets are not specified.
- Alternative interpretations: None. The campaign is clearly a malicious cyberattack leveraging AI hype as a social engineering lure.
This incident is a financially motivated cybercrime campaign leveraging the popularity of generative AI tools as social engineering lures to distribute information-stealing malware. While it poses a threat to individual privacy and digital security, it has minor national security implications and can be managed through standard cybersecurity practices.
- Overall national security impact: Minor
- Response level: Moderate
- Scope: Multiple nations
- Primary target: No clear primary
- Other affected: Unknown
- Alleged perpetrator: Vietnamese cybercriminals
Threat characteristics
- Imminence: Near-term. The campaign is currently active on social media and requires ongoing monitoring and standard defensive updates.
- Autonomy: Human-controlled. The attack relies on human-designed social engineering lures and standard malware, with no autonomous AI decision-making involved.
- Novelty: Evolved capability. Represents an evolution of existing social engineering techniques, specifically exploiting public interest in generative AI tools to distribute malware.
Impact by dimension
- Physical security: Negligible. No threat to physical systems, critical infrastructure, or human safety was reported in connection with this cybercrime campaign.
- Information security: Negligible. The campaign is a financially motivated cybercrime operation and does not involve state-sponsored information warfare or compromise of intelligence capabilities.
- Sovereignty: Negligible. There is no indication of impact on government decision-making, electoral systems, or core state authority.
- Economic security: Minor. The malware targets individual credentials and cryptocurrency wallets, representing minor economic impact manageable through standard cybersecurity measures.
- Societal stability: Minor. The incident involves privacy violations and data theft of individual victims, but does not threaten overall societal stability or human rights.