Close Menu
  • Home
  • AI Models
    • DeepSeek
    • xAI
    • OpenAI
    • Meta AI Llama
    • Google DeepMind
    • Amazon AWS AI
    • Microsoft AI
    • Anthropic (Claude)
    • NVIDIA AI
    • IBM WatsonX Granite 3.1
    • Adobe Sensi
    • Hugging Face
    • Alibaba Cloud (Qwen)
    • Baidu (ERNIE)
    • C3 AI
    • DataRobot
    • Mistral AI
    • Moonshot AI (Kimi)
    • Google Gemma
    • xAI
    • Stability AI
    • H20.ai
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Microsoft Research
    • Meta AI Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding & Startups
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • Expert Insights & Videos
    • Google DeepMind
    • Lex Fridman
    • Matt Wolfe AI
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • Matt Wolfe AI
    • The TechLead
    • Andrew Ng
    • OpenAI
  • Expert Blogs
    • François Chollet
    • Gary Marcus
    • IBM
    • Jack Clark
    • Jeremy Howard
    • Melanie Mitchell
    • Andrew Ng
    • Andrej Karpathy
    • Sebastian Ruder
    • Rachel Thomas
    • IBM
  • AI Policy & Ethics
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
    • EFF AI
    • European Commission AI
    • Partnership on AI
    • Stanford HAI Policy
    • Mozilla Foundation AI
    • Future of Life Institute
    • Center for AI Safety
    • World Economic Forum AI
  • AI Tools & Product Releases
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
    • Image Generation
    • Video Generation
    • Writing Tools
    • AI for Recruitment
    • Voice/Audio Generation
  • Industry Applications
    • Finance AI
    • Healthcare AI
    • Legal AI
    • Manufacturing AI
    • Media & Entertainment
    • Transportation AI
    • Education AI
    • Retail AI
    • Agriculture AI
    • Energy AI
  • AI Art & Entertainment
    • AI Art News Blog
    • Artvy Blog » AI Art Blog
    • Weird Wonderful AI Art Blog
    • The Chainsaw » AI Art
    • Artvy Blog » AI Art Blog
What's Hot

UniMMVSR: A Unified Multi-Modal Framework for Cascaded Video Super-Resolution – Takara TLDR

Training-Free Group Relative Policy Optimization – Takara TLDR

Singapore company allegedly helped China smuggle $2 billion worth of Nvidia AI processors, report claims — Nvidia denies that the accused has any China ties, but a U.S. investigation is underway

Facebook X (Twitter) Instagram
Advanced AI News
  • Home
  • AI Models
    • OpenAI (GPT-4 / GPT-4o)
    • Anthropic (Claude 3)
    • Google DeepMind (Gemini)
    • Meta (LLaMA)
    • Cohere (Command R)
    • Amazon (Titan)
    • IBM (Watsonx)
    • Inflection AI (Pi)
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Meta AI Research
    • Microsoft Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • AI Experts
    • Google DeepMind
    • Lex Fridman
    • Meta AI Llama
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • The TechLead
    • Matt Wolfe AI
    • Andrew Ng
    • OpenAI
    • Expert Blogs
      • François Chollet
      • Gary Marcus
      • IBM
      • Jack Clark
      • Jeremy Howard
      • Melanie Mitchell
      • Andrew Ng
      • Andrej Karpathy
      • Sebastian Ruder
      • Rachel Thomas
      • IBM
  • AI Tools
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
  • AI Policy
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
  • Business AI
    • Advanced AI News Features
    • Finance AI
    • Healthcare AI
    • Education AI
    • Energy AI
    • Legal AI
LinkedIn Instagram YouTube Threads X (Twitter)
Advanced AI News
Video Generation

New Noodlophile Malware Spreads Through Fake AI Video Generation Platforms

By Advanced AI EditorMay 12, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


Cybercriminals have unleashed a new malware campaign using fake AI video generation platforms as a lure.

Dubbed Noodlophile Stealer, this previously undocumented infostealer targets unsuspecting users by exploiting their enthusiasm for AI-powered content creation tools.

Disguised as legitimate services promising to transform images into videos, these fraudulent platforms-often promoted through viral social media campaigns and Facebook groups with thousands of views-trick users into downloading malicious payloads that harvest browser credentials, cryptocurrency wallets, and other sensitive data.

– Advertisement –
Google News
Noodlophile Malware
Fake AI Platforms Amplified by Facebook

In many instances, the malware also deploys a remote access trojan (RAT) like XWorm, granting attackers deeper control over compromised systems.

Cybercriminals Exploit AI Hype

The attack chain begins when users, lured by advertisements on platforms mimicking popular tools like Luma Dream Machine or CapCut, upload personal images or videos to these fake websites.

After a deceptive loading screen, victims are prompted to download their “processed” content, which is actually a malicious ZIP archive such as VideoDreamAI.zip.

Inside, a deceptive executable named Video Dream MachineAI.mp4.exe masquerades as a video file through clever filename manipulation.

Upon execution, this 32-bit C++ binary-repurposed from a legitimate version of CapCut-initiates a multi-stage infection process.

It launches CapCut.exe, a 140MB C++ wrapper embedding .NET malicious code, designed to evade static scanners through its sheer size and modular structure.

According to Morphisec Report, This loader verifies internet connectivity by pinging Google up to 10 times, renames disguised files like Document.docx to install.bat, and triggers further infection stages involving Base64-encoded archives and Python payloads fetched from remote servers.

The final payload, Noodlophile Stealer, exfiltrates data via Telegram bots, while XWorm facilitates propagation through techniques like PE hollowing into legitimate processes like RegAsm.exe or direct shellcode injection, enhancing evasion.

What sets this campaign apart is its exploitation of AI as a social engineering vector, targeting a trusting audience of creators and small businesses exploring AI for productivity.

Unlike traditional phishing or pirated software lures, these attackers capitalize on the novelty and perceived legitimacy of AI tools.

Open-source intelligence (OSINT) investigations reveal the developer behind Noodlophile, likely of Vietnamese origin based on social media indicators, actively markets this malware on cybercrime forums as part of a malware-as-a-service (MaaS) model.

The sophisticated obfuscation-combining Base64 encoding, password-protected archives, and memory-based execution-makes detection and analysis challenging, while persistence mechanisms via Windows Registry keys ensure long-term access.

This campaign underscores the evolving tactics of cybercriminals who adapt to emerging tech trends, turning public curiosity into a gateway for data theft and system compromise.

As AI adoption surges, users must remain vigilant, verifying the authenticity of platforms and avoiding unsolicited downloads, while organizations like Morphisec advocate for proactive defenses like Automated Moving Target Defense (AMTD) to neutralize such stealthy threats before execution.

Indicators of Compromise (IOCs)

TypeIndicatorC2 URLshttp://lumalabs-dream[.]com/VideoLumaAI.zip, https://luma-dreammachine[.]com/LumaAI.zipIP Addresses149.154.167.220 (Telegram APIs), 103.232.54[.]13:25902 (XWorm C2)Hashes5c98553c45c9e86bf161c7b5060bd40ba5f4f11d5672ce36cd2f30e8c7016424 (VideoDreamAI.zip)Tokens7882816556:AAEEosBLhRZ8Op2ZRmBF1RD7DkJIyfk47Ds (randomuser2025)

Setting Up SOC Team? – Download Free Ultimate SIEM Pricing Guide (PDF) For Your SOC Team -> Free Download



Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleIBM Think 2025 Showcases Watsonx.data’s Role In Generative AI
Next Article Efficient Sensorimotor Learning for Open-world Robot Manipulation
Advanced AI Editor
  • Website

Related Posts

Try Free Sora 2 AI Video Generator On Sara2.ai — No Invite Code Or App Needed — KHTS Radio — Santa Clarita Radio

October 11, 2025

Google TV could soon let you create AI videos right from your couch

October 10, 2025

Why AI Video Creation in 2025 Is Still Far from Perfect

October 10, 2025
Leave A Reply

Latest Posts

The Rubin Names 2025 Art Prize, Research and Art Projects Grants

Kochi-Muziris Biennial Announces 66 Artists for December Exhibition

Instagram Launches ‘Rings’ Awards for Creators—With KAWS as a Judge

Museums Prepare to Close Their Doors as Government Shutdown Continues

Latest Posts

UniMMVSR: A Unified Multi-Modal Framework for Cascaded Video Super-Resolution – Takara TLDR

October 12, 2025

Training-Free Group Relative Policy Optimization – Takara TLDR

October 12, 2025

Singapore company allegedly helped China smuggle $2 billion worth of Nvidia AI processors, report claims — Nvidia denies that the accused has any China ties, but a U.S. investigation is underway

October 12, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • UniMMVSR: A Unified Multi-Modal Framework for Cascaded Video Super-Resolution – Takara TLDR
  • Training-Free Group Relative Policy Optimization – Takara TLDR
  • Singapore company allegedly helped China smuggle $2 billion worth of Nvidia AI processors, report claims — Nvidia denies that the accused has any China ties, but a U.S. investigation is underway
  • Memory Retrieval and Consolidation in Large Language Models through Function Tokens – Takara TLDR
  • When You Tell AI Models to Act Like Women, Most Become More Risk-Averse: Study

Recent Comments

  1. RoyalThroneF3Nalay on United States, China, and United Kingdom Lead the Global AI Ranking According to Stanford HAI’s Global AI Vibrancy Tool
  2. KevinCar on [2102.10717] Abstraction and Analogy-Making in Artificial Intelligence
  3. RoyalThroneF3Nalay on Former Sotheby’s Vet Launches Art Lending Firm with Nahmads’ Backing
  4. RoyalThroneF3Nalay on Paper page – Generative Blocks World: Moving Things Around in Pictures
  5. WhirlwindLuckC9Nalay on United States, China, and United Kingdom Lead the Global AI Ranking According to Stanford HAI’s Global AI Vibrancy Tool

Welcome to Advanced AI News—your ultimate destination for the latest advancements, insights, and breakthroughs in artificial intelligence.

At Advanced AI News, we are passionate about keeping you informed on the cutting edge of AI technology, from groundbreaking research to emerging startups, expert insights, and real-world applications. Our mission is to deliver high-quality, up-to-date, and insightful content that empowers AI enthusiasts, professionals, and businesses to stay ahead in this fast-evolving field.

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

LinkedIn Instagram YouTube Threads X (Twitter)
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2025 advancedainews. Designed by advancedainews.

Type above and press Enter to search. Press Esc to cancel.