Noodlophile Stealer Reportedly Distributed Through Allegedly Fraudulent AI Content Platforms
A campaign reportedly used fake AI video generation sites to distribute malware under the guise of AI-generated content. Promoted via social media, these sites allegedly tricked users into downloading files containing Noodlophile Stealer, a previously unreported infostealer, and in some cases XWorm. The malware harvested credentials and could enable remote access.
- Date it happened
- 2025-05-08
- Organisation involved
- Noodlophile Stealer developers, Unknown actors operating fraudulent AI-themed websites, Unknown actors distributing malware-as-a-service (MaaS)
- Product, system or model
- zlib, XWorm, WinRAR CLI utility, Windows Registry, Windows, Telegram, RegAsm.exe, Python marshal, PowerShell, Luma Dreammachine, Google, Fake AI content generation platforms, Facebook, Dream Machine,
This incident was imported from AI Incident Database and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.
This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.