Skip to content
← Back to newsCybercriminals Exploit AI Trend to Distribute Noodlophile Malware to Over 62,000 Users
Markets

Cybercriminals Exploit AI Trend to Distribute Noodlophile Malware to Over 62,000 Users

By DarshitaNewcomer0 rep· 5/13/2025

Cybercriminals are leveraging the popularity of artificial intelligence (AI) tools to distribute a new malware strain known as Noodlophile. This sophisticated campaign has already targeted over 62,000 users through fake AI platforms advertised on social media, particularly Facebook.

 

Key Takeaways

  • Malware Distribution: Fake AI tools are being used to spread Noodlophile malware, which steals sensitive information.

  • Social Media Exploitation: The campaign primarily uses Facebook ads to lure users into downloading malicious software.

  • Multi-Stage Attack: The infection process involves several deceptive steps, making it difficult for users to detect.

  • Data Theft: Noodlophile targets browser credentials, cryptocurrency wallets, and other sensitive data.

 

The Rise of Noodlophile Malware

The Noodlophile malware is a new addition to the cybercriminal toolkit, designed to harvest sensitive information from unsuspecting users. It is primarily distributed through fake AI video generation tools that promise users advanced capabilities but instead deliver malicious payloads.

Cybersecurity researchers from Morphisec have identified that these fake platforms often mimic legitimate services, such as the popular Luma Dream Machine, and are heavily promoted on Facebook. Some posts have garnered over 62,000 views, indicating the effectiveness of this deceptive strategy.

 

How the Attack Works

The attack follows a multi-stage infection process:

  1. User Engagement: Victims are drawn to fake AI tools advertised on social media.

  2. File Upload: Users are prompted to upload images or videos for processing.

  3. Malicious Download: Instead of receiving an AI-generated video, users download a ZIP file containing a malicious executable disguised as a video file.

  4. Execution of Malware: When the executable is run, it initiates a series of actions that lead to the installation of the Noodlophile Stealer.

 

Technical Details of Noodlophile

  • Deceptive Naming: The malicious executable is named Video Dream MachineAI.mp4.exe, misleading users into thinking it is a video file.

  • Multi-Layered Payload: The malware uses a hidden folder containing additional malicious files, including a modified version of the legitimate CapCut video editing tool.

  • Persistence Mechanism: The malware establishes persistence on the infected system by creating registry entries and executing scripts that ensure it remains active even after a reboot.

  • Data Exfiltration: Stolen data, including browser credentials and cryptocurrency wallet information, is sent to attackers via a Telegram bot, providing real-time access to the compromised information.

 

The Broader Implications

The emergence of Noodlophile highlights a concerning trend in cybercrime, where attackers exploit the growing interest in AI technologies to deceive users. This tactic not only targets individual users but also poses a significant risk to businesses that rely on AI tools for operations.

As the popularity of AI continues to rise, so does the potential for malicious actors to create convincing scams. Users are urged to exercise caution when downloading software from unknown sources and to verify the legitimacy of any AI tools before use.

 

Conclusion

The Noodlophile malware campaign serves as a stark reminder of the evolving landscape of cyber threats. As cybercriminals become more sophisticated in their tactics, it is crucial for users to remain vigilant and informed about potential risks associated with downloading software from social media and other unverified platforms. By taking proactive measures, individuals can better protect themselves against these emerging threats.

 

Sources

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

Cybercriminals Exploit AI Trend to Distribute Noodlophile Malware to Over 62,000 Users | BlockzHub