logo

FIN7 Hosting Honeypot Domains with Malicious AI DeepNude Generators – New Silent Push Research

ID: 6f9f6c0f-935e-56c4-859e-cbebfa4963d8

STIX ID: report--6f9f6c0f-935e-56c4-859e-cbebfa4963d8

Feed Name: infostealers.com

Threat Score
80/100

Date Published: 2024-10-03

Date Updated: 2026-07-21

Author: Alon Gal

...
...

Silent Push analysts report that FIN7 is actively using at least seven ‘AI DeepNude’ websites and malvertising (including “Requires Browser Extension” .MSIX lures) to distribute NetSupport RAT, infostealers (RedLine, Lumma), and loaders (D3F@ck), with multiple observed domains, IPs, C2s and sample artifacts; the campaign uses multi-stage packing/obfuscation, DLL side‑loading and Java wrappers, and leverages SEO and file-hosting redirects to scale distribution, putting corporate credentials and domain-joined networks at risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.