logo

New Noodlophile Stealer Distributes Via Fake AI Video Generation Platforms

ID: 62ebb1bf-e97c-57b0-968c-9a8115b77c2f

STIX ID: report--62ebb1bf-e97c-57b0-968c-9a8115b77c2f

Feed Name: Morphisec Blog

Threat Score
75/100

Date Published: 2025-05-08

Date Updated: 2026-04-28

Author: Shmuel Uzan

...
...

Morphisec details a widespread social-engineering campaign that impersonates AI-based media generation services to trick users into downloading a ZIP archive which installs a multi-stage malware chain: a repackaged CapCut binary that unpacks and runs .NET and Python components, the Noodlophile infostealer (credential and wallet theft) and optionally an XWorm loader providing remote access and worm-like propagation; the report includes technical analysis, persistence/evade techniques (LOLBins, in-memory execution, PE hollowing), developer OSINT, and a comprehensive set of IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.