logo

Fake AI Tools Push New Noodlophile Stealer Through Facebook Ads

ID: 4ffd36ba-f0cb-5294-88e6-b31cf1549e5a

STIX ID: report--4ffd36ba-f0cb-5294-88e6-b31cf1549e5a

Feed Name: HackRead

Threat Score
75/100

Date Published: 2025-05-08

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Morphisec disclosed a multi-stage campaign that lures victims with fake AI video/image generation sites (promoted via Facebook) to download a ZIP containing a malicious CapCut-branded executable that unpacks and installs the Noodlophile stealer and an XWorm loader. The report details infection TTPs (signed repurposed executable, password-protected archives, Python payloads, in-memory execution, shellcode injection/PE hollowing), exfiltration via Telegram, and attribution leads to an individual likely promoting the malware on social platforms and marketplaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.