216.73.216.6

Vietnam-Nexus Hackers Distribute Malware Via Fake AI Video Generators

· Published 28/05/2025 17:57 · Modified 28/05/2025 20:51

Export JSON

Essential information

Published
28/05/2025 17:57
Modified
28/05/2025 20:51
Tags
2025-05-28 ai video generators backdoor frostrift grimpull infostealer noodlophile stealer social media ads starkveil vietnam xworm
Related entities
1 observables, 1 intrusion sets (apt), 6 techniques (mitre), 5 malware, 1 others

Description

A hacking group with alleged ties to has been exploiting promoting to distribute malware since mid-2024. The campaign, discovered by Mandiant, uses fake websites mimicking legitimate AI tools to deploy payloads including Python-based infostealers and backdoors. The group, tracked as UNC6032, has reached millions of users through Facebook and LinkedIn ads, primarily targeting EU countries and the US. The malware distributed includes , , , and , designed for information theft and capable of downloading additional plugins. The attackers employ a multi-payload mechanism for resilience against detection. Users are advised to exercise caution when engaging with AI tools and verify website legitimacy.

External references