EXECUTIVE SUMMARY
In recent weeks, cybercriminals have used fake AI images and video generators to spread information-stealing malware that targets both Windows and macOS systems. The malware campaigns use fake websites that appear to offer legitimate AI applications, specifically EditProAI, an image and video editor. These fake sites infect users with two different types of malwares: Lumma Stealer for Windows and AMOS for macOS. Both types are designed to steal sensitive information, including passwords, credentials, cryptocurrency wallets, credit card details, and browsing history. The malware gathers this data from popular browsers like Google Chrome, Microsoft Edge, and Mozilla Firefox. The stolen information is then packaged into an archive and sent to the attacker’s server, where it can be used for further attacks or sold on the dark web. This method highlights the growing threat of information-stealing malware, which has become more dangerous as it takes advantage of the popularity of AI tools, tricking users into downloading harmful software through convincing fake websites.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
In recent weeks, cybercriminals have used fake AI images and video generators to spread information-stealing malware that targets both Windows and macOS systems. The malware campaigns use fake websites that appear to offer legitimate AI applications, specifically EditProAI, an image and video editor. These fake sites infect users with two different types of malwares: Lumma Stealer for Windows and AMOS for macOS. Both types are designed to steal sensitive information, including passwords, credentials, cryptocurrency wallets, credit card details, and browsing history. The malware gathers this data from popular browsers like Google Chrome, Microsoft Edge, and Mozilla Firefox. The stolen information is then packaged into an archive and sent to the attacker’s server, where it can be used for further attacks or sold on the dark web. This method highlights the growing threat of information-stealing malware, which has become more dangerous as it takes advantage of the popularity of AI tools, tricking users into downloading harmful software through convincing fake websites.[emaillocker id="1283"]
The methods behind the Lumma Stealer and AMOS malware campaigns are carefully planned. Cybercriminals have created fake websites promoting EditProAI, a video and image editing software, and used ads and search engine results to attract victims. These sites look convincing and often feature attention-grabbing content, like deepfake political videos, to lure people in. Once a user clicks on the site, they are taken to a download link that installs the malware. The Windows version of the malware is called "Edit-ProAI-Setup-newest_release.exe," and the macOS version is "EditProAi_v.4.36.dmg." The Windows malware is signed with a stolen code-signing certificate from Softwareok.com, which makes it seem trustworthy. Once installed, the malware steals data such as passwords, cookies, cryptocurrency wallet info, and credit card details from the user’s browser. This data is then sent to the attacker’s server, where it can be accessed and used. The malware uses a special panel to send the stolen data. The popularity of AI tools makes this type of attack effective, as it tricks users into thinking they are downloading something useful.
The appearance of Lumma Stealer and AMOS shows a worrying trend in cybercrime, where criminals are using fake AI tools to spread information-stealing malware. As AI technology becomes more popular, criminals are finding new ways to trick people into downloading harmful software. Victims of these attacks face serious risks, including identity theft, financial loss, and the exposure of private information. If someone has downloaded these fake applications, they should change their passwords right away, especially for important accounts related to finances or cryptocurrency. Using multi-factor authentication on these accounts is also important to protect against further attacks. The rise of information-stealing malware highlights the need for more awareness about online security and being careful when visiting unfamiliar websites or downloading software. As these attacks become more common, it’s crucial for both individuals and businesses to strengthen their cybersecurity defenses to avoid falling victim to this growing threat.
THREAT PROFILE:
| Tactic | Technique ID | Technique |
| Execution | T1203 | Exploitation for Client Execution |
| Defense Evasion | T1075 | Use Alternate Authentication Material |
| T1112 | Modify Registry | |
| Credential Access | T1003 | OS Credential Dumping |
| Collection | T1074 | Data Staged |
| Command and Control | T1071 | Application Layer Protocol |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| Impact | T1486 | Data Encrypted for Impact |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]