Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse

Report 4362

Associated Incidents

Incident 8655 Report
Fake AI 'Nudify' Sites Reportedly Linked to Malware Distribution by Russian Hacker Collective FIN7

Loading...
Tracking FIN7 malware honeypots, new AI deepfake lures
virusbulletin.com · 2024

FIN7 (also known as Sangria Tempest) is a financially motivated threat group with links to Russia, that has been operating since at least 2013, and that was previously thought to have been eliminated by the DOJ.

From a single origin point, Silent Push threat analysts uncovered an extensive series of ongoing FIN7 campaigns, including several hundred active phishing, spoofing, shell and malware delivery domains and IPs targeting the numerous enterprise organizations and products.

We found thousands of parked FIN7 domains, and by monitoring these daily for changes, we’ve been able to find malicious infrastructure as soon as it launches. One of the most recent FIN7 malware delivery lures is being used across several domains and promotes 'AI Deepfake Nude Generating Software', which leads to D3F@ck Loader and at least one additional payload.

Other software being targeted with fake websites and malicious payloads includes 7-zip, PuTTY, ProtectedPDFViewer, AIMP, Notepad++, Advanced IP Scanner, AnyDesk, pgAdmin, AutoDesk, Bitwarden, Rest Proxy, Python, Sublime Text, and Node.js.

Our presentation will highlight current methods FIN7 is using to target enterprise organizations with ransomware payloads, and details about the malware we’ve seen across the group's infrastructure in 2024.

Read the Source

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2024 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • e1b50cd