Charts
DataOn-chain
VIP
Market Cap
API
Rankings
CoinOSNew
CoinClaw🦞
Language
  • 简体中文
  • 繁体中文
  • English
Leader in global market data applications, committed to providing valuable information more efficiently.

Features

  • Real-time Data
  • Special Features
  • AI Grid

Services

  • News
  • Open Data(API)
  • Institutional Services

Downloads

  • Desktop
  • Android
  • iOS

Contact Us

  • Chat Room
  • Business Email
  • Official Email
  • Official Verification

Join Community

  • Telegram
  • Twitter
  • Discord

© Copyright 2013-2026. All rights reserved.

简体繁體English
|Legacy

Fake AI Tools Used to Spread Noodlophile Crypto Wallet Stealing Malware

CN
Decrypt
Follow
10 months ago
AI summarizes in 5 seconds.

People are being tricked into downloading fake AI tools as a way to spread the information stealer malware Noodlophile.


This malware is able to harvest browser credentials, cryptocurrency wallet information and more sensitive data, according to a security researcher.


Morphisec researcher Shmuel Uzan said, in a report, "Instead of relying on traditional phishing or cracked software sites, they build convincing AI-themed platforms – often advertised via legitimate-looking Facebook groups and viral social media campaigns."


The attackers build convincing AI themed platforms which can then be advertised on Facebook groups or social media campaigns. While these may look legitimate, they are simply fronts to get people to download the malware hidden in what appears to be AI tools.


These sorts of posts, shared on Facebook, have reached views as high as 62,000, from a single post alone.


Some of the fake social media pages identified are: Luma Dreammachine AI, Luma Dreammaching and gratistuslibros.


Once a user clicks on a post they are taken to apparently free AI editing tools and urged to upload their image or video. They are then asked to download what looks like the AI tool, but is actually a malicious ZIP archive called VideoDreamAI.zip. This leads to a Python binary paving the way to deploy the Noodlophile Stealer.


Some instances have also seen the data stealer bundled with remote access trojans like XWorm, for more control over the host's machine and data.


The Noodlophile malware is assessed to be of Vietnamese origin, according to a GitHub profile that claims to be that of "a passionate Malware Developer from Vietnam."


Authorities have said that cybercrime is especially prevalent in Southeast Asia and there is a history of distributing stealer software using the Facebook platform specifically.


Edited by Stacy Elliott.


免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

返20%!Boost新规,参与平分+交易量多赚
广告
|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

Selected Articles by Decrypt

1 hour ago
Polymarket Inks US, Canada Deal with European Soccer League LaLiga
12 hours ago
Naoris Launches Post-Quantum Blockchain as Bitcoin, Ethereum Devs Scramble to Face Threat
14 hours ago
Google Researchers Reveal Every Way Hackers Can Trap, Hijack AI Agents
View More

Table of Contents

|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

Related Articles

avatar
avatarcoindesk
11 seconds ago
Crypto snoozes into Good Friday as oil and macro stir: Crypto Daybook Americas
avatar
avatarbitcoin.com
13 minutes ago
Bitget Launches VIP Fast Track Program Across Futures, Spot and Asset Holdings
avatar
avatarbitcoin.com
43 minutes ago
OpenAI Acquires TBPN Podcast Startup to Shape Global Narrative on AI
avatar
avatarcoindesk
44 minutes ago
Crypto consolidates as volatility cools and futures markets tilt bearish
avatar
avatarDecrypt
1 hour ago
Polymarket Inks US, Canada Deal with European Soccer League LaLiga
APP
Windows
Mac

X

Telegram

Facebook

Reddit

CopyLink