Close Menu
Alan C. Moore
    What's Hot

    Red carpet welcome? Saudi Arabia rolls out a lavender one for US president

    May 13, 2025

    Pakistan envoy to Bangladesh goes on sudden leave, sparks speculation

    May 13, 2025

    Israeli officials: Conducted air strikes in Khan Younis to kill Yahya Sinwar’s brother

    May 13, 2025
    Facebook X (Twitter) Instagram
    Trending
    • Red carpet welcome? Saudi Arabia rolls out a lavender one for US president
    • Pakistan envoy to Bangladesh goes on sudden leave, sparks speculation
    • Israeli officials: Conducted air strikes in Khan Younis to kill Yahya Sinwar’s brother
    • Trump lifts Syria sanctions, seals massive Saudi investment deals during Gulf visit
    • India expresses concern over ban on Awami League, Dhaka responds
    • Anita Anand named Canada foreign minister
    • Expert Highlights Illegal Alien Gang’s Threat to Rural Americans
    • 10 dead bodies found near Portland since mid-April
    Alan C. MooreAlan C. Moore
    Subscribe
    Wednesday, May 14
    • Home
    • US News
    • Politics
    • Business & Economy
    • Video
    • About Alan
    • Newsletter Sign-up
    Alan C. Moore
    Home » Blog » Noodlophile Malware Distributed Through Bogus AI Video Generators: Who Are the Targets?

    Noodlophile Malware Distributed Through Bogus AI Video Generators: Who Are the Targets?

    May 13, 2025Updated:May 13, 2025 Tech No Comments
    noodlophile malware fraudulent website jpeg
    noodlophile malware fraudulent website jpeg
    Share
    Facebook Twitter LinkedIn Pinterest Email
    A picture of a phony site that purports to be an AI video service meant to entice users to download malware. Morphisec as an photo

    Users are being conned into getting malware by phony AI software by cybercriminals. The site offers a downloadable report with an infostealer after a person uploads their own image as a fast.

    In a statement, Morphisec’s security researcher Shmuel Uzan wrote that this file installs malware on its systems, including Noodlophile and Noodlophile, which are included in XWorm. This will make it possible for attackers to steal data, obtain credentials, and possibly gain remote access to infected devices.

    Fake AI devices are promoted on Twitter.

    As attackers post hyperlinks to” AI-themed platforms” in groups where people are looking for free Artificial resources, the new social engineering movement appears to be beginning on Facebook. These organizations have thousands of members, and content in them can have as many as 62, 000 opinions, according to Uzan.

    Victims of the fake websites that offer the allegedly AI services imitate reputable application, using fake names and logos like Luma Dream Machine. One also includes the popular video editing item CapCut logo, which is owned by TikTok family company ByteDance.

    The sites encourage visitors to publish their own videos or images, claiming AI will be used to change the files or create new content using the prompts. The program “processes” the guide file after uploading it before displaying a Download Now button.

    Observe: TechRepublic Premium’s Malware Quick Glossary.

    Victims become infected when they attempt to get AI-generated content.

    When the survivor presses the download button, it downloads a ZIP report with the name VideoDreamAI. a.NET load, C++-based executables, and sample scripts are all contained in postal, which contains a number of components. Video Dream Machine AI, an binary. mp4. the next, CapCut, is launched by file. executes the.NET load before running.

    The load installs a Python load called srchost. Executes an infostealer that collects the defendant’s website qualifications, biscuits, crypto wallets, currencies, and other data when it is executed from a remote server. This has been nicknamed the Noodlophile Infostealer and you use a Telegram app to transmit the stolen information to the intruders. A distant access troy like XWorm is occasionally loaded in some cases.

    Must-read safety cover

    What makes this battle special, and who is the target?

    The false platforms exposed by Uzan also offer AI-generated sites and mockups, which suggests that the suspect’s targets are businesses. However, their usage of Facebook groups for promotion suggests that they aren’t interested in big business clients but quite small or medium-sized businesses looking for free marketing tools to lower costs.

    What makes this strategy unique is how it uses AI as a social executive trap, turning an emerging reasonable pattern into an illness vector, Uzan wrote. This procedure targets a newer, more trustworthy market: authors and small firms looking to use AI for productivity, in contrast to older malware activities that are disguised as pirated application or game cheats.

    Noodlophile is thought to have its origins in Vietnam.

    On crime forums, searching for the name” Noodlophile” revealed that it was being promoted as a component of a malware-as-a-service giving, according to Uzan. Additionally, he discovered the malware’s creator on Facebook, who frequently posted comments on articles that promoted an account-takeover tactic used by the Noodlophile infostealer.

    Uzan believes the creator is Asian because of the language and other social multimedia signals. The associated GitHub report claims to be a “passionate Malware Developer” who sells virtual safety equipment, and has removed the name Noodlophile.

    Source credit

    Keep Reading

    Android Unveils One of Its ‘Biggest Updates in Years’ at I/O Event

    Android Unveils One of Its ‘Biggest Updates in Years’ at I/O Event

    Trump Expected to Use AI Chips Dominance to Forge Middle East Deals

    Trump Expected to Use AI Chips Dominance to Forge Middle East Deals

    iPhone Users’ Wait for Better Battery Life May Be Over With iOS 19

    Samsung Galaxy S25 Edge Unveiled: Slimmer, Lighter, Smarter – Preorder Now

    Editors Picks

    Red carpet welcome? Saudi Arabia rolls out a lavender one for US president

    May 13, 2025

    Pakistan envoy to Bangladesh goes on sudden leave, sparks speculation

    May 13, 2025

    Israeli officials: Conducted air strikes in Khan Younis to kill Yahya Sinwar’s brother

    May 13, 2025

    Trump lifts Syria sanctions, seals massive Saudi investment deals during Gulf visit

    May 13, 2025

    India expresses concern over ban on Awami League, Dhaka responds

    May 13, 2025

    Anita Anand named Canada foreign minister

    May 13, 2025

    Expert Highlights Illegal Alien Gang’s Threat to Rural Americans

    May 13, 2025

    10 dead bodies found near Portland since mid-April

    May 13, 2025

    Zelenskyy urges Trump to attend peace talks, but Putin’s plans still unclear

    May 13, 2025

    Depardieu found guilty of sexual assault, gets 18-month suspended sentence

    May 13, 2025
    • Home
    • US News
    • Politics
    • Business & Economy
    • About Alan
    • Contact

    Sign up for the Conservative Insider Newsletter.

    Get the latest conservative news from alancmoore.com [aweber listid="5891409" formid="902172699" formtype="webform"]
    Facebook X (Twitter) YouTube Instagram TikTok
    © 2025 alancmoore.com
    • Privacy Policy
    • Terms
    • Accessibility

    Type above and press Enter to search. Press Esc to cancel.