Today > 2 Critical | 3 High | 25 Medium vulnerabilities   -   You can now download lists of IOCs here!

Fake AI video generators infect Windows, macOS with infostealers

Nov. 18, 2024, 5:03 p.m.

Description

Threat actors are using fake AI image and video generators to distribute Lumma Stealer and AMOS information-stealing malware on Windows and macOS. These malicious programs masquerade as an AI application called EditProAI, targeting users through search results and social media advertisements. The malware steals credentials, passwords, credit card information, and cryptocurrency wallets from popular web browsers. Victims are lured by deepfake political videos and professional-looking websites. The Windows variant uses a stolen code signing certificate to appear legitimate. Users who have downloaded this malware should consider their saved passwords and authentication compromised, reset them immediately, and enable multi-factor authentication on sensitive accounts.

Date

Published: Nov. 16, 2024, 9:56 p.m.

Created: Nov. 16, 2024, 9:56 p.m.

Modified: Nov. 18, 2024, 5:03 p.m.

Attack Patterns

Lumma Stealer

AMOS

T1216

T1588.002

T1204.001

T1012

T1552

T1114

T1087

T1056.001

T1555

T1005

T1083

T1566