logo

FIN7 hackers launch deepfake nude “generator” sites to spread malware

ID: 22e9ad71-6426-5f25-97c2-568f65d47263

STIX ID: report--22e9ad71-6426-5f25-97c2-568f65d47263

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-10-02

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

FIN7 operated a network of fake AI "deepnude" sites promoted via black-hat SEO and malvertising to trick users into downloading archives that deployed information-stealing malware (notably Lumma Stealer, Redline Stealer, D3F@ck Loader) and other payloads such as NetSupport RAT; the campaign harvested browser credentials, cookies, and cryptocurrency wallets and is linked to FIN7's broader criminal activity including ties to ransomware groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.