"Disguised" as an AI tool on Facebook, luring users into a malware trap
Many Facebook users have been tricked into downloading malware disguised as AI tools, causing personal information and cryptocurrency wallets to be silently stolen.
Báo Khoa học và Đời sống•16/05/2025
A new type of malware called “Noodlophile” is spreading rapidly on Facebook through fake AI tools. (Photo: morphisec) Pages like “Luma Dreammachine AI” or “CapCut AI” pretend to be artificial intelligence video and image creation platforms to trick users. (Photo: morphisec) When users access it, they are directed to software download links that appear trustworthy, but actually contain malicious code. (Photo: morphisec) The downloaded file is named “VideoDreamAI.zip”, inside is a dangerous file with the extension “.mp4.exe” to trick users’ eyes. (Photo: morphisec) When launched, the file triggers an infection chain, planting malware that can steal login credentials, cryptocurrency wallet data, and personal accounts. (Photo: eSecurity Planet) The malware can also install the XWorm trojan, allowing hackers to remotely control the computer without the victim's knowledge. (Photo: Decrypt) According to security firm Morphisec, the malware development group may originate from Southeast Asia, where Facebook scams frequently occur. (Photo: Bleeping Computer) Users need to be wary of free AI software promoted on social media and should only download from official sites to avoid becoming a victim. (Photo: Digital Watch Observat)
Comment (0)