Fake AI 'Nudify' Sites Reportedly Linked to Malware Distribution by Russian Hacker Collective FIN7

October 2, 2024

Investigations by Silent Push reveal that the hacker group FIN7 is suspected of creating fraudulent AI 'nudify' websites to distribute malware. These sites reportedly entice users seeking deepfake AI tools into downloading malware disguised as nudify software. The malicious program steals sensitive data, which can be utilized for extortion or financial fraud. Notably, FIN7's activities in this domain are said to signify the resurrection of a group once declared defunct by the U.S. Department of Justice.

For those interested in shaping the future of responsible AI and AI governance, join HISPI Project Cerebellum and contribute to our efforts to establish guardrails for AI, prevent harm, and measure the impact of AI incidents such as this one within our AI incident database. JOIN US

Matched TAIM controls

Suggested mapping from embedding similarity (not a formal assessment). Browse all TAIM controls

Alleged deployer
fin7, carbon-spider, elbrus, sangria-tempest
Alleged developer
fin7, carbon-spider, elbrus, sangria-tempest
Alleged harmed parties
users-of-fake-nudify-sites

Source

Data from the AI Incident Database (AIID). Cite this incident: https://incidentdatabase.ai/cite/865

Data source

Incident data is from the AI Incident Database (AIID).

When citing the database as a whole, please use:

McGregor, S. (2021) Preventing Repeated Real World AI Failures by Cataloging Incidents: The AI Incident Database. In Proceedings of the Thirty-Third Annual Conference on Innovative Applications of Artificial Intelligence (IAAI-21). Virtual Conference.

Pre-print on arXiv · Database snapshots & citation guide

We use weekly snapshots of the AIID for stable reference. For the official suggested citation of a specific incident, use the “Cite this incident” link on each incident page.