Threat Advisory

Fake AI Generators Spread Information-Stealing Malware on Windows and macOS

Threat: Malware
Targeted Sector: Technology & IT, Finance & Banking
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

In recent weeks, cybercriminals have used fake AI images and video generators to spread information-stealing malware that targets both Windows and macOS systems. The malware campaigns use fake websites that appear to offer legitimate AI applications, specifically EditProAI, an image and video editor. These fake sites infect users with two different types of malwares: Lumma Stealer for Windows and AMOS for macOS. Both types are designed to steal sensitive information, including passwords, credentials, cryptocurrency wallets, credit card details, and browsing history. The malware gathers this data from popular browsers like Google Chrome, Microsoft Edge, and Mozilla Firefox. The stolen information is then packaged into an archive and sent to the attacker’s server, where it can be used for further attacks or sold on the dark web. This method highlights the growing threat of information-stealing malware, which has become more dangerous as it takes advantage of the popularity of AI tools, tricking users into downloading harmful software through convincing fake websites.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

In recent weeks, cybercriminals have used fake AI images and video generators to spread information-stealing malware that targets both Windows and macOS systems. The malware campaigns use fake websites that appear to offer legitimate AI applications, specifically EditProAI, an image and video editor. These fake sites infect users with two different types of malwares: Lumma Stealer for Windows and AMOS for macOS. Both types are designed to steal sensitive information, including passwords, credentials, cryptocurrency wallets, credit card details, and browsing history. The malware gathers this data from popular browsers like Google Chrome, Microsoft Edge, and Mozilla Firefox. The stolen information is then packaged into an archive and sent to the attacker’s server, where it can be used for further attacks or sold on the dark web. This method highlights the growing threat of information-stealing malware, which has become more dangerous as it takes advantage of the popularity of AI tools, tricking users into downloading harmful software through convincing fake websites.[emaillocker id="1283"]

The methods behind the Lumma Stealer and AMOS malware campaigns are carefully planned. Cybercriminals have created fake websites promoting EditProAI, a video and image editing software, and used ads and search engine results to attract victims. These sites look convincing and often feature attention-grabbing content, like deepfake political videos, to lure people in. Once a user clicks on the site, they are taken to a download link that installs the malware. The Windows version of the malware is called "Edit-ProAI-Setup-newest_release.exe," and the macOS version is "EditProAi_v.4.36.dmg." The Windows malware is signed with a stolen code-signing certificate from Softwareok.com, which makes it seem trustworthy. Once installed, the malware steals data such as passwords, cookies, cryptocurrency wallet info, and credit card details from the user’s browser. This data is then sent to the attacker’s server, where it can be accessed and used. The malware uses a special panel to send the stolen data. The popularity of AI tools makes this type of attack effective, as it tricks users into thinking they are downloading something useful.

 

The appearance of Lumma Stealer and AMOS shows a worrying trend in cybercrime, where criminals are using fake AI tools to spread information-stealing malware. As AI technology becomes more popular, criminals are finding new ways to trick people into downloading harmful software. Victims of these attacks face serious risks, including identity theft, financial loss, and the exposure of private information. If someone has downloaded these fake applications, they should change their passwords right away, especially for important accounts related to finances or cryptocurrency. Using multi-factor authentication on these accounts is also important to protect against further attacks. The rise of information-stealing malware highlights the need for more awareness about online security and being careful when visiting unfamiliar websites or downloading software. As these attacks become more common, it’s crucial for both individuals and businesses to strengthen their cybersecurity defenses to avoid falling victim to this growing threat.

THREAT PROFILE:

Tactic Technique ID Technique
Execution T1203 Exploitation for Client Execution
Defense Evasion T1075 Use Alternate Authentication Material
T1112 Modify Registry
Credential Access T1003 OS Credential Dumping
Collection T1074 Data Staged
Command and Control T1071 Application Layer Protocol
Exfiltration T1041 Exfiltration Over C2 Channel
Impact T1486 Data Encrypted for Impact

REFERENCES:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/fake-ai-video-generators-infect-windows-macos-with-infostealers/

[/emaillocker]
crossmenu