Close Menu
  • Home
  • AI Models
    • DeepSeek
    • xAI
    • OpenAI
    • Meta AI Llama
    • Google DeepMind
    • Amazon AWS AI
    • Microsoft AI
    • Anthropic (Claude)
    • NVIDIA AI
    • IBM WatsonX Granite 3.1
    • Adobe Sensi
    • Hugging Face
    • Alibaba Cloud (Qwen)
    • Baidu (ERNIE)
    • C3 AI
    • DataRobot
    • Mistral AI
    • Moonshot AI (Kimi)
    • Google Gemma
    • xAI
    • Stability AI
    • H20.ai
  • AI Research
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Microsoft Research
    • Meta AI Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding & Startups
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • Expert Insights & Videos
    • Google DeepMind
    • Lex Fridman
    • Matt Wolfe AI
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • Matt Wolfe AI
    • The TechLead
    • Andrew Ng
    • OpenAI
  • Expert Blogs
    • François Chollet
    • Gary Marcus
    • IBM
    • Jack Clark
    • Jeremy Howard
    • Melanie Mitchell
    • Andrew Ng
    • Andrej Karpathy
    • Sebastian Ruder
    • Rachel Thomas
    • IBM
  • AI Policy & Ethics
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
    • EFF AI
    • European Commission AI
    • Partnership on AI
    • Stanford HAI Policy
    • Mozilla Foundation AI
    • Future of Life Institute
    • Center for AI Safety
    • World Economic Forum AI
  • AI Tools & Product Releases
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
    • Image Generation
    • Video Generation
    • Writing Tools
    • AI for Recruitment
    • Voice/Audio Generation
  • Industry Applications
    • Finance AI
    • Healthcare AI
    • Legal AI
    • Manufacturing AI
    • Media & Entertainment
    • Transportation AI
    • Education AI
    • Retail AI
    • Agriculture AI
    • Energy AI
  • AI Art & Entertainment
    • AI Art News Blog
    • Artvy Blog » AI Art Blog
    • Weird Wonderful AI Art Blog
    • The Chainsaw » AI Art
    • Artvy Blog » AI Art Blog
What's Hot

Productivity Commission targets AI, renewables to lift economy

United States, China, and United Kingdom Lead the Global AI Ranking According to Stanford HAI’s Global AI Vibrancy Tool

OM1’s PhenOM® Foundation AI Surpasses One Billion Years of Health History in Model Training | National Business

Facebook X (Twitter) Instagram
Advanced AI News
  • Home
  • AI Models
    • Adobe Sensi
    • Aleph Alpha
    • Alibaba Cloud (Qwen)
    • Amazon AWS AI
    • Anthropic (Claude)
    • Apple Core ML
    • Baidu (ERNIE)
    • ByteDance Doubao
    • C3 AI
    • Cohere
    • DataRobot
    • DeepSeek
  • AI Research & Breakthroughs
    • Allen Institue for AI
    • arXiv AI
    • Berkeley AI Research
    • CMU AI
    • Google Research
    • Meta AI Research
    • Microsoft Research
    • OpenAI Research
    • Stanford HAI
    • MIT CSAIL
    • Harvard AI
  • AI Funding & Startups
    • AI Funding Database
    • CBInsights AI
    • Crunchbase AI
    • Data Robot Blog
    • TechCrunch AI
    • VentureBeat AI
    • The Information AI
    • Sifted AI
    • WIRED AI
    • Fortune AI
    • PitchBook
    • TechRepublic
    • SiliconANGLE – Big Data
    • MIT News
    • Data Robot Blog
  • Expert Insights & Videos
    • Google DeepMind
    • Lex Fridman
    • Meta AI Llama
    • Yannic Kilcher
    • Two Minute Papers
    • AI Explained
    • TheAIEdge
    • Matt Wolfe AI
    • The TechLead
    • Andrew Ng
    • OpenAI
  • Expert Blogs
    • François Chollet
    • Gary Marcus
    • IBM
    • Jack Clark
    • Jeremy Howard
    • Melanie Mitchell
    • Andrew Ng
    • Andrej Karpathy
    • Sebastian Ruder
    • Rachel Thomas
    • IBM
  • AI Policy & Ethics
    • ACLU AI
    • AI Now Institute
    • Center for AI Safety
    • EFF AI
    • European Commission AI
    • Partnership on AI
    • Stanford HAI Policy
    • Mozilla Foundation AI
    • Future of Life Institute
    • Center for AI Safety
    • World Economic Forum AI
  • AI Tools & Product Releases
    • AI Assistants
    • AI for Recruitment
    • AI Search
    • Coding Assistants
    • Customer Service AI
    • Image Generation
    • Video Generation
    • Writing Tools
    • AI for Recruitment
    • Voice/Audio Generation
  • Industry Applications
    • Education AI
    • Energy AI
    • Finance AI
    • Healthcare AI
    • Legal AI
    • Media & Entertainment
    • Transportation AI
    • Manufacturing AI
    • Retail AI
    • Agriculture AI
  • AI Art & Entertainment
    • AI Art News Blog
    • Artvy Blog » AI Art Blog
    • Weird Wonderful AI Art Blog
    • The Chainsaw » AI Art
    • Artvy Blog » AI Art Blog
Advanced AI News
Home » Vietnam-Nexus Hackers Distribute Malware Via Fake AI Video Generators
Video Generation

Vietnam-Nexus Hackers Distribute Malware Via Fake AI Video Generators

Advanced AI BotBy Advanced AI BotMay 28, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


A hacking group allegedly from Vietnam has been leveraging social media ads promoting generative AI tools to distribute malware since at least mid-2024, according to Google Cloud-owned Mandiant.

On May 27, Google Cloud released a new report detailing the findings of a Mandiant Threat Defense investigation initiated in November 2024.

The malicious campaign, which began at least as early as mid-2024, leverages the interest in AI tools, particularly AI-powered video-generating services, to distribute malware leading to the deployment of payloads such as Python-based infostealers and several backdoors.

The campaign was attributed to a group tracked as UNC6032, which the Google Threat Intelligence Group (GTIG) assessed as having a connection to Vietnam.

Findings from this report align with a May 8 Morphisec report on Noodlophile Stealer, a newly discovered infostealer of likely Vietnamese origin.

UNC6032’sTypical Infection Chain

In the campaign discovered by Mandiant, UNC6032 utilized fake ‘AI video generator’ websites to distribute malware.

Here is the typical infection chain:

Victims are directed to fake websites via malicious social media ads on Facebook – from either an attacker-created Facebook page or a compromised Facebook account – and LinkedIn that masquerade as legitimate AI video generator tools like Luma AI, Canva Dream Lab and Kling AI, among others
Once they click on one of the malicious ads, they are directed to fake websites that offer purported functionalities, such as text-to-video or image-to-video generation
Once the user provides a prompt to generate a video, regardless of the input, the website will serve one of the static payloads hosted on the same (or related) infrastructure
The payloads include the STARKVEIL dropper, which deploys the XWORM and FROSTRIFT backdoors and the GRIMPULL downloader

UNC6032’s Campaign Overview

Mandiant has identified over 30 different websites mentioned across thousands of UNC6032-linked ads that have collectively reached millions of users. Most ads were found on Facebook and a handful on LinkedIn.

The researchers then performed further analysis of a sample of over 120 malicious Facebook ads, revealing a total reach of more than 2.3 million users across EU countries.

“It should be noted that reach does not equate to the number of victims. According to Meta, the reach of an ad is an estimated number of how many Account Center accounts saw the ad at least once,” noted the Mandiant report.

Typically, UNC6032 constantly rotates the domains mentioned in the Facebook ads, likely to avoid detection and account bans.

“We noted that once a domain is registered, it will be referenced in ads within a few days if not the same day. Moreover, most of the ads are short-lived, with new ones being created on a daily basis,” the researchers added.

On LinkedIn, they identified roughly 10 malicious ads, with a total impression estimate of 50,000 to 250,000 – with US-based viewers being the majority, followed by users in Europe and Australia. Each ad directed users to hxxps://klingxai[.]com, a domain registered on September 19, 2024. The first malicious LinkedIn ad appeared just a day later.

“We suspect similar campaigns are active on other platforms as well, as cybercriminals consistently evolve tactics to evade detection and target multiple platforms to increase their chances of success,” the researchers added.

UNC6032’s Resilience With Multi-Payload Mechanism

For all these ads, the payload downloaded is the STARKVEIL malware, which typically drops three different modular malware families (the XWORM and FROSTRIFT backdoors and the GRIMPULL downloader), primarily designed for information theft and capable of downloading plugins to extend their functionality.

XWORM was also detected by Morphisec as one of the distributed payloads alongside Noodlophile Stealer.

The Google Cloud report provides malware analyses for STARKVEIL, XWORM, FROSTRIFT and GRIMPULL, as well as details about how they communicate with UNC6032’s command-and-control (C2) infrastructure.

Mandiant assessed that the presence of multiple, similar payloads suggests a fail-safe mechanism, allowing the attack to persist even if some payloads are detected or blocked by security defenses.

“Although our investigation was limited in scope, we discovered that well-crafted fake ‘AI websites’ pose a significant threat to both organizations and individual users. These AI tools no longer target just graphic designers; anyone can be lured in by a seemingly harmless ad,” the Mandiant researchers concluded.

“The temptation to try the latest AI tool can lead to anyone becoming a victim. We advise users to exercise caution when engaging with AI tools and to verify the legitimacy of the website’s domain.”



Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleMistral AI Empowers Developers With Full Agents API Toolkit
Next Article Gemma 3N: Google’s Latest On Device Mobile AI Model
Advanced AI Bot
  • Website

Related Posts

This Dreamlike Video Generator Makes Interactive AI Feel Like a Lo-Fi Acid Trip

May 29, 2025

Fake AI Video Tool Ads on Facebook, LinkedIn Spread Infostealers

May 28, 2025

I just used Veo 3 to create a wild AI video and it’s easier than you think

May 28, 2025
Leave A Reply Cancel Reply

Latest Posts

The Kooks Luke Pritchard On New Music, Fatherhood And More

James Rondeau Returns as Director of Art Institute of Chicago

Centre Pompidou to Open New Brazil Satellite

Lincoln Center Theater Celebrates Four Decades Of Impact And Artistry

Latest Posts

Productivity Commission targets AI, renewables to lift economy

May 30, 2025

United States, China, and United Kingdom Lead the Global AI Ranking According to Stanford HAI’s Global AI Vibrancy Tool

May 30, 2025

OM1’s PhenOM® Foundation AI Surpasses One Billion Years of Health History in Model Training | National Business

May 30, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Welcome to Advanced AI News—your ultimate destination for the latest advancements, insights, and breakthroughs in artificial intelligence.

At Advanced AI News, we are passionate about keeping you informed on the cutting edge of AI technology, from groundbreaking research to emerging startups, expert insights, and real-world applications. Our mission is to deliver high-quality, up-to-date, and insightful content that empowers AI enthusiasts, professionals, and businesses to stay ahead in this fast-evolving field.

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

YouTube LinkedIn
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2025 advancedainews. Designed by advancedainews.

Type above and press Enter to search. Press Esc to cancel.