FIN7 Hosting Honeypot Domains with Malicious AI DeepNude Generators – New Silent Push Research
ID: 6f9f6c0f-935e-56c4-859e-cbebfa4963d8
STIX ID: report--6f9f6c0f-935e-56c4-859e-cbebfa4963d8
Feed Name: infostealers.com
Silent Push analysts report that FIN7 is actively using at least seven ‘AI DeepNude’ websites and malvertising (including “Requires Browser Extension” .MSIX lures) to distribute NetSupport RAT, infostealers (RedLine, Lumma), and loaders (D3F@ck), with multiple observed domains, IPs, C2s and sample artifacts; the campaign uses multi-stage packing/obfuscation, DLL side‑loading and Java wrappers, and leverages SEO and file-hosting redirects to scale distribution, putting corporate credentials and domain-joined networks at risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
