Fake AI Tools Spread Noodlophile Malware via Social Media Platforms

Fake AI Platforms on Social Media Spreading Vietnamese-Linked Noodlophile Malware to Steal Sensitive Data

  • Cybercriminals are using fake Artificial Intelligence (AI) platforms on social media to trick people into downloading Noodlophile Malware.
  • These platforms distribute malicious ZIP files that steal sensitive information like browser passwords and cryptocurrency wallet details.
  • Noodlophile is believed to have originated in Vietnam and sometimes includes extra software for remote computer access.

Cybercriminals are targeting users by promoting fake AI tools on social media, leading to the spread of the Noodlophile malware, according to recent findings by security researchers. Users are drawn in by what appear to be legitimate AI editing platforms, then tricked into downloading files that actually contain information-stealing malware.

- Advertisement -

Security researcher Shmuel Uzan from Morphisec reported that attackers set up convincing AI-themed sites and advertise them through Facebook groups and viral social posts. Large numbers of users are being reached—one post alone was viewed more than 62,000 times. When users follow links to these sites, they are prompted to download what looks like a useful tool but is actually a malicious ZIP file named VideoDreamAI.zip.

The Noodlophile malware hidden inside these downloads is able to collect browser credentials, cryptocurrency wallet information, and other sensitive data. According to Uzan’s report, "instead of relying on traditional phishing or cracked software sites, they build convincing AI-themed platforms – often advertised via legitimate-looking Facebook groups and viral social media campaigns." The platforms identified so far include fake names like Luma Dreammachine AI, Luma Dreammaching, and gratistuslibros.

Once a victim clicks to download the supposed AI tool, the ZIP archive deploys a Python binary that installs the Noodlophile Stealer. This software can collect sensitive information and, in some cases, is bundled with additional remote access trojans such as XWorm. These trojans give attackers further control over the infected computer.

The source of Noodlophile appears to be connected to Vietnam, with a GitHub profile describing its owner as "a passionate Malware Developer from Vietnam." Authorities say Southeast Asia, and especially Facebook, have seen repeated cybercriminal activity involving information-stealing malware.

- Advertisement -

These incidents show cybercriminals are taking advantage of the popularity of AI tools and the reach of social media to spread malware and collect personal information from unsuspecting users.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Appeal rejected for French tax agent who leaked targets case

Ghalia C., a 32-year-old tax agent at the Bobigny tax office, used internal software...

Altcoin Rotation: XRP, Solana Rally as Bitcoin Consolidates.

Selective altcoins, led by XRP and Solana, have outperformed majors amid market consolidation.Analysts describe...

XRP Could Reach $6.20 If Market Cap Equals Ethereum by 2027?

XRP rose sharply in 2025, topping $3 in January and reaching $3.65 in July.If...

Paradox Founder Linked to UK Illegal Weight-Loss Ring Probed

Fasial Tariq, co-founder of Paradox Metaverse, is linked to a UK industrial unit raided...

Institutions Ramp Up ETH Staking as SharpLink Yields Surge!!

SharpLink Gaming earned 10,657 ETH (about $33 million) in staking rewards over the past...
- Advertisement -

Must Read

7 Best Audiobooks on Cybersecurity

Cybersecurity has become an essential topic in our increasingly digital world. As technology evolves and becomes more integrated into our daily lives, the importance...
Bitcoin (BTC) $ 91,314.00 0.74%
Ethereum (ETH) $ 3,118.37 0.60%
XRP (XRP) $ 2.13 0.07%
Bittensor (TAO) $ 290.07 0.68%
Polkadot (DOT) $ 2.11 1.69%
Cardano (ADA) $ 0.398621 1.02%
Chainlink (LINK) $ 13.30 0.33%
Hyperliquid (HYPE) $ 25.61 1.93%
Monero (XMR) $ 457.21 1.09%
Hedera (HBAR) $ 0.122266 0.66%
Toncoin (TON) $ 1.78 5.91%