Mandiant Flags Fake AI Video Generators Laced with Malware
- Since mid-2024, the cybercriminal group UNC6032 has been using fraudulent websites that mimic AI-powered video creation tools to deliver malware, leveraging misleading advertisements on social networking sites such as Facebook and LinkedIn to attract victims.
- The campaign takes advantage of rising demand for AI-driven video creation platforms by guiding users to fraudulent websites that imitate well-known prompt-to-video services such as those offered by leading AI tool providers.
- Thousands of advertisements have targeted millions worldwide, tricking victims into downloading malware like Python-based infostealers and backdoors that harvest login details, browsing session data, payment information, and sometimes Facebook account specifics.
- The malware includes modular components like the Rust-based STARKVEIL dropper and COILHATCH Python scripts that exfiltrate data via the Telegram API, and the group is suspected to have a nexus to Vietnam without confirmed state ties.
- This campaign turns a legitimate AI trend into a malware vector, prompting urgent recommendations to verify AI tool legitimacy and exercise caution against malvertising and evolving cyber threats.
14 Articles
14 Articles
Mandiant flags fake AI video generators laced with malware
As the internet fills up with clips from AI-video generators, hacking groups are seeding the online landscape with malware-laced programs and fake websites hoping to cash in on the trend. Tracked by researchers at Mandiant and Google Cloud, the campaign is being carried out by a group identified as “UNC6032.” Since mid-2024, they have spread thousands of advertisements, fake websites and social media posts promising victims access to popular pro…


Threat Actors Weaponize Fake AI-Themed Websites to Deliver Python-based infostealers
Mandiant Threat Defense has uncovered a malicious campaign orchestrated by the threat group UNC6032, which capitalizes on the global fascination with artificial intelligence (AI). Since at least mid-2024, UNC6032 has been deploying fake AI video generator websites to distribute malware, specifically targeting users through deceptive social media ads on platforms like Facebook and LinkedIn. These […] The post Threat Actors Weaponize Fake AI-Theme…
Coverage Details
Bias Distribution
- 100% of the sources are Center
To view factuality data please Upgrade to Premium
Ownership
To view ownership data please Upgrade to Vantage