CyberWire Daily
CyberWire Daily
N2K Networks
A new stealer hiding behind AI hype. [Research Saturday]
22 minutes Posted Nov 29, 2025 at 8:00 am.
0:00
22:08
Download MP3
Show notes

Please enjoy this encore of Research Saturday.

This week, we are joined by ⁠Michael Gorelik⁠, Chief Technology Officer from ⁠Morphisec⁠, discussing their work on "New Noodlophile Stealer Distributes Via Fake AI Video Generation Platforms." A new threat dubbed Noodlophile Stealer is exploiting the popularity of AI-powered content tools by posing as fake AI video generation platforms, luring users into uploading media in exchange for malware-laced downloads.

Distributed through convincing Facebook groups and viral campaigns, the malware steals browser credentials, cryptocurrency wallets, and can deploy a remote access trojan like XWorm. The campaign uses a layered, obfuscated delivery chain disguised as legitimate video editing software, making it both deceptive and difficult to detect.

The research can be found here:

Learn more about your ad choices. Visit megaphone.fm/adchoices