Vietnam-Nexus Hackers Distribute Malware Via Fake AI Video Generators
Essential information
- Published
- 28/05/2025 17:57
- Modified
- 28/05/2025 20:51
- Tags
- 2025-05-28 ai video generators backdoor frostrift grimpull infostealer noodlophile stealer social media ads starkveil vietnam xworm
- Related entities
- 1 observables, 1 intrusion sets (apt), 6 techniques (mitre), 5 malware, 1 others
Description
A hacking group with alleged ties to Vietnam has been exploiting social media ads promoting AI video generators to distribute malware since mid-2024. The campaign, discovered by Mandiant, uses fake websites mimicking legitimate AI tools to deploy payloads including Python-based infostealers and backdoors. The group, tracked as UNC6032, has reached millions of users through Facebook and LinkedIn ads, primarily targeting EU countries and the US. The malware distributed includes STARKVEIL, XWORM, FROSTRIFT, and GRIMPULL, designed for information theft and capable of downloading additional plugins. The attackers employ a multi-payload mechanism for resilience against detection. Users are advised to exercise caution when engaging with AI tools and verify website legitimacy.