{"id":5617,"date":"2024-10-03T04:55:55","date_gmt":"2024-10-03T09:55:55","guid":{"rendered":"https:\/\/www.darkreading.com\/endpoint-security\/ai-nude-photo-generator-delivers-infostealers"},"modified":"2024-10-03T04:55:55","modified_gmt":"2024-10-03T09:55:55","slug":"ai-nude-photo-generator-delivers-infostealers-instead-of-images","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/10\/03\/ai-nude-photo-generator-delivers-infostealers-instead-of-images\/","title":{"rendered":"AI &#8216;Nude Photo Generator&#8217; Delivers Infostealers Instead of Images"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt2d9897d9b1105f2b\/66fe6d99730a528bb4a9faae\/deepfake-mike-adobestock.jpeg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-nude-photo-generator-delivers-infostealers-instead-of-images.png?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-nude-photo-generator-delivers-infostealers-instead-of-images.png?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The notorious <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/fin7-evolves-into-a-broader-more-dangerous-threat-group\" rel=\"noopener\">FIN7 threat group<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> is combining artificial intelligence (AI) with social engineering in an aggressive, adult-themed threat campaign that dangles lures for access to technology that can &#8220;deepfake&#8221; nude photos \u2014 all to fool people into installing infostealing malware.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The powerful Russian financial cybercrime group has created at least seven websites that advertise for what&#8217;s called a &#8220;DeepNude Generator,&#8221; which promises to use deepfake technology transform any photo into a nude representation of the person pictured, according to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.silentpush.com\/blog\/fin7-malware-deepfake-ai-honeypot\/#Initial-findings\" rel=\"noopener\">new research<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> from the threat hunters at Silent Push.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">People can either download the generator via the site or sign up for a &#8220;free trial,&#8221; demonstrating the sophistication of the scam. But instead of receiving the tool, they end up downloading malicious payloads such as the stealers Lumma and Redline, which can be used to deliver further malware such as ransomware, the researchers said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Given the provocative lure, organizations are vulnerable to the campaign, as it may entice &nbsp;unsuspecting employees to download malicious files. &#8220;These files may directly compromise credentials via infostealers or be used for follow-on campaigns that deploy ransomware,&#8221; according to a blog post about the research.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Meanwhile, FIN7 also continues to promote an existing malvertising campaign that targets corporate users with lures to content by popular brands \u2014 including &nbsp;SAP Concur, Microsoft, Thomson Reuters, and FINVIZ stock screening \u2014 &nbsp;to spread the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/battleroyal-hackers-deliver-darkgate-rat\" rel=\"noopener\">NetSupport RAT<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and .MSIX malware, according to Silent Push. The researchers identified a number of active IPs and thus &#8220;active new websites&#8221; hosting the ploy, which asks people to download a fake &#8220;required browser extension,&#8221; which is actually a malicious payload, to view content related to the brands.<\/span><\/p>\n<p data-component=\"related-article\" class=\"RelatedArticle\"><span data-testid=\"related-article-title\" class=\"RelatedArticle-Title\">Related:<\/span><a class=\"RelatedArticle-RelatedContent\" data-discover=\"true\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/python-malware-slithers-legit-vs-code\" target=\"_self\" rel=\"noopener\">Python-Based Malware Slithers Into Systems via Legit VS Code<\/a><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Fin7 Evolves With the Times\">Fin7 Evolves With the Times<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The DeepNude Generator campaign demonstrates particularly sophisticated thought and planning on the part of FIN7, which developed at least seven dedicated websites URLs \u2014such as aiNude[.]ai, easynude[.]website, and ai-nude[.]cloud \u2014 to make it appear convincing.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">There is also evidence that FIN7 is employing search engine optimization (SEO) to keep users engaged and to rank their honeypots higher in search results by using footer links to &#8220;Best Porn Sites&#8221; on its sites. Those links direct victims to other malicious sites dangling the same lure.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Moreover, the group invested effort in creating two website versions for promoting the deepfake tool. The first involves a DeepNude Generator &#8220;free download,&#8221; and the second offers site visitors a DeepNude Generator &#8220;free trial,&#8221; each with a different attack flow. &nbsp;<\/span><\/p>\n<p data-component=\"related-article\" class=\"RelatedArticle\"><span data-testid=\"related-article-title\" class=\"RelatedArticle-Title\">Related:<\/span><a class=\"RelatedArticle-RelatedContent\" data-discover=\"true\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/dragos-expands-ics-platform-acquisition\" target=\"_self\" rel=\"noopener\">Dragos Expands ICS Platform With New Acquisition<\/a><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The first uses &#8220;a simple user flow&#8221; that uses a &#8220;free download&#8221; link leading users to a new domain featuring a Dropbox link or another source hosting a malicious payload, according to Silent Push.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The second attack flow prompts users via a &#8220;free trial&#8221; button to upload an image to test the generator. If this is done, the user is next prompted with a \u201ctrial is ready for download\u201d message, with a corresponding pop-up requires the user to answer the question: &#8220;The link is for personal use only, do you agree?&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;If the user agrees and clicks &#8216;download,&#8217; they are served a .zip file with a malicious payload&#8221; that leads to the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/weaponized-youtube-channels-spread-lumma-stealer\" rel=\"noopener\">Lumma Stealer<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and which uses a DLL side-loading technique for execution, according to Silent Push.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Mitigation &amp; Defense Against Fin7\">Mitigation &amp; Defense Against Fin7<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The two campaigns demonstrate that FIN7 \u2014 a cybercrime collective also known as Carbanak, Carbon Spider, Cobalt Group, and Navigator Group that&#8217;s been active since 2012 \u2014 remains an imminent threat despite <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/feds-indict-three-ukrainians-for-cyberattacks-on-100-companies\" rel=\"noopener\">many attempts by law enforcement<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/high-level-fin7-admin-sentenced-to-10-years-in-prison\" rel=\"noopener\">shut it down<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, or at least significantly disrupt it. It also shows a tenacity on the group&#8217;s part to evolve with modern technology and psychological tactics to create more sophisticated ways to spread malware, the researchers said.<\/span><\/p>\n<p data-component=\"related-article\" class=\"RelatedArticle\"><span data-testid=\"related-article-title\" class=\"RelatedArticle-Title\">Related:<\/span><a class=\"RelatedArticle-RelatedContent\" data-discover=\"true\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/millions-kia-vehicles-remote-hacks-license-plate\" target=\"_self\" rel=\"noopener\">Millions of Kia Vehicles Open to Remote Hacks via License Plate<\/a><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Indeed, FIN7 has long been known for its savvy combination of malware and social engineering, having mounted a slew of successful, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/security-end-run-aukill-shuts-down-windows-reliant-edr-processes\" rel=\"noopener\">financially motivated attacks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> against global organizations that have hauled in well over $1.2 billion \u2014 and counting \u2014 for the criminal enterprise.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To help organizations combat threats from FIN7 and other organized cybercriminal groups, developing indicators of attack based on the group&#8217;s tactics, techniques, and procedures (TTPs) is one method. Also, training employees to be aware of these increasingly elaborate social engineering tactics that threat groups use, and blocking the download of any unknown any files from the Internet onto a machine connected to a corporate network also can help enterprises avoid compromise by sophisticated threat campaigns.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/endpoint-security\/ai-nude-photo-generator-delivers-infostealers\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The notorious FIN7 threat group is combining artificial intelligence (AI)<\/p>\n","protected":false},"author":12,"featured_media":5618,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5617","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-nude-photo-generator-delivers-infostealers-instead-of-images.png?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-nude-photo-generator-delivers-infostealers-instead-of-images.png?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-nude-photo-generator-delivers-infostealers-instead-of-images.png?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-nude-photo-generator-delivers-infostealers-instead-of-images.png?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-nude-photo-generator-delivers-infostealers-instead-of-images.png?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-nude-photo-generator-delivers-infostealers-instead-of-images.png?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-nude-photo-generator-delivers-infostealers-instead-of-images.png?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-nude-photo-generator-delivers-infostealers-instead-of-images.png?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-nude-photo-generator-delivers-infostealers-instead-of-images.png?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-nude-photo-generator-delivers-infostealers-instead-of-images.png?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/ai-nude-photo-generator-delivers-infostealers-instead-of-images.png?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5617","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5617"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5617\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5618"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5617"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5617"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5617"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}