Fake AI Tools Push New Noodlophile Stealer Through Facebook Ads
ID: 4ffd36ba-f0cb-5294-88e6-b31cf1549e5a
STIX ID: report--4ffd36ba-f0cb-5294-88e6-b31cf1549e5a
Feed Name: HackRead
Morphisec disclosed a multi-stage campaign that lures victims with fake AI video/image generation sites (promoted via Facebook) to download a ZIP containing a malicious CapCut-branded executable that unpacks and installs the Noodlophile stealer and an XWorm loader. The report details infection TTPs (signed repurposed executable, password-protected archives, Python payloads, in-memory execution, shellcode injection/PE hollowing), exfiltration via Telegram, and attribution leads to an individual likely promoting the malware on social platforms and marketplaces.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
