Fake AI 'Nudify' Sites Reportedly Linked to Malware Distribution by Russian Hacker Collective FIN7

The Russian hacker group FIN7 has launched a campaign using fake 'nudify' websites to distribute infostealer malware. These sites lure users interested in AI-generated nonconsensual nude imagery by offering 'free downloads' or 'free trials' of deepfake software. Instead of providing the promised AI functionality, the sites deliver malicious payloads, including Redline Stealer, Lumma Stealer, and NetSupport RAT, which are used to harvest credentials and facilitate financial fraud or ransomware attacks.

The hacker group FIN7 is allegedly behind fake AI "nudify" websites distributing infostealer malware to users, according to an investigation by Silent Push. These sites are reported to lure individuals seeking deepfake AI tools into downloading malware disguised as software to "nudify" photos. The malware steals sensitive data from victims, which is used for extortion or financial fraud. FIN7's activity on this front reportedly marks the revival of a group previously declared defunct by the U.S. Department of Justice.

Source: AI Incident Database

Risk classification

  • Primary risk domain: 4 Malicious actors
  • Primary risk subdomain: 4.3 Fraud, scams, and targeted manipulation

The threat actors used the lure of AI deepfake generation tools to orchestrate a scam, deceiving users into downloading credential-stealing malware for financial gain.

Causal factors

  • Entity: Human
  • Intent: Intentional
  • Timing: Post-deployment

The risk and subsequent harm were directly caused by human threat actors (FIN7) intentionally deploying malicious honeypot websites that leveraged the popularity of generative AI as a lure.

EU AI Act risk tier

  • Risk tier: 3 Limited Risk

Limited Risk: The campaign leveraged the concept of AI-generated deepfakes. Under the EU AI Act, AI-generated content such as deepfakes falls under Limited Risk (Level 3) due to transparency obligations, though the actual system here was a malicious spoof.

AI system and alleged parties

  • AI system: AI adult-based generator
  • AI purpose: Deepfake Image Generation; Visual Art Generation
  • Behaviour type: unknown
  • Alleged developer: Sangria Tempest, FIN7, ELBRUS, Carbon Spider
  • Alleged deployer: Sangria Tempest, FIN7, ELBRUS, Carbon Spider
  • Alleged harmed parties: Users of fake nudify sites

Harm severity

Highest direct severity in any category: Substantial. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.

  • Physical: direct Negligible, indirect Negligible
  • Infrastructure: direct Negligible, indirect Negligible
  • Property: direct Negligible, indirect Negligible
  • Financial: direct Negligible, indirect Negligible
  • Environmental: direct Negligible, indirect Negligible
  • Malicious content: direct Negligible, indirect Negligible
  • Differential treatment: direct Negligible, indirect Negligible
  • Civil rights: direct Negligible, indirect Negligible
  • Democracy: direct Negligible, indirect Negligible
  • Privacy: direct Minor, indirect Negligible
  • Psychological: direct Negligible, indirect Negligible
  • Epistemic: direct Negligible, indirect Negligible
  • Child sexual exploitation and abuse: direct Negligible, indirect Negligible

Privacy

Reported: The report explicitly describes the deployment of infostealer malware designed to obtain cookies, passwords, and other credentials from victims.

Directly caused: The malware directly stole sensitive personal data, credentials, and cookies from infected user devices.

Indirectly caused: N/A

Inferred additional harm: It is highly likely that stolen credentials were used to access private accounts, corporate networks, and personal data, violating the privacy of numerous individuals.

People affected

  • Occurrences reported: 1

Potential causes

Management

  • Lack of Enterprise Domain Blocking: Organizations fail to block access to shady AI deepfake honeypots.

Technology

  • Generative AI Image Models: Public availability of generative AI image models enables deepfake site creation.
  • Malware Wrapped in AI Tools: Threat actors hide info-stealers inside fake AI generator executables.

Data Inputs

  • User Photo Uploads: Users upload real-life photos to fake AI sites, exposing private data.

Human Factors

  • Demand for Nonconsensual AI Nudes: Users proactively seek creepy deepfake AI software, ignoring safety risks.
  • Unsuspecting Employee Actions: Employees download malicious files, compromising domain-joined machines.

Process and Methods

  • SEO Manipulation of AI Sites: Threat actors use SEO tactics to boost malicious AI sites in search results.
  • Deceptive Free Trial Flows: Sophisticated multi-step trials trick users into downloading payloads.

Regulatory Environment

  • Proliferation of Nudify Websites: Rapid rise of deepfake sites outpaces legal and regulatory enforcement.

Information quality

  • Classification confidence: High
  • Reason for confidence: The reports from Silent Push and other cybersecurity outlets provide highly detailed technical analysis of the malware, domain names, and the mechanics of the FIN7 campaign. The role of AI as a social engineering lure is clearly documented, leaving little ambiguity about the nature of the threat.
  • Ambiguities identified: The exact number of victims who downloaded the malware is not specified.
  • Alternative interpretations: None. The campaign is clearly a financially motivated cyberattack using AI-themed social engineering.

The Russian cybercriminal group FIN7 exploited public interest in AI deepfake generators by setting up fake 'nudify' websites to distribute infostealer malware. While the incident demonstrates how generative AI trends are used as social engineering lures, the actual national security impact remains minor, primarily posing traditional cybersecurity and financial fraud risks.

  • Overall national security impact: Minor
  • Response level: Moderate
  • Scope: Multiple nations
  • Primary target: No clear primary
  • Other affected: Unknown
  • Alleged perpetrator: FIN7

Threat characteristics

  • Imminence: Long-term. This represents an ongoing cybercriminal tactic and malware distribution campaign rather than an immediate national security crisis.
  • Autonomy: Human-controlled. The campaign relied entirely on human actors setting up malicious sites and SEO; no autonomous AI systems were deployed.
  • Novelty: Evolved capability. Evolves traditional phishing and malware distribution by capitalizing on the high demand and public interest in generative AI 'nudify' tools.

Impact by dimension

  • Physical security: Negligible. No physical infrastructure, kinetic systems, or human safety elements were targeted or affected by this cyber campaign.
  • Information security: Minor. Credential-stealing malware was distributed to individuals and corporate networks, posing a minor threat to information security but with no coordinated state disinformation.
  • Sovereignty: Negligible. No government decision-making, electoral systems, or core state functions were disrupted or targeted.
  • Economic security: Minor. Financial fraud and potential ransomware deployment represent minor economic threats, but do not threaten strategic industries or national economic stability.
  • Societal stability: Negligible. Although exploiting interest in nonconsensual deepfakes, the campaign did not generate toxic content or cause large-scale social instability.
Explore in the interactive Incident Tracker