Noodlophile Stealer Reportedly Distributed Through Allegedly Fraudulent AI Content Platforms

May 8, 2025

A recent incident involved the reported distribution of malware through allegedly fraudulent AI content platforms. The campaign, promoted via social media, tricked users into downloading files containing Noodlophile Stealer, a previously unreported infostealer, and in some cases XWorm. These malicious programs harvested credentials and granted remote access. This serves as an important reminder for the need of trustworthy AI governance and safe and secure AI practices.

For those interested in shaping responsible AI policies and contributing to harm prevention, JOIN US. By joining HISPI Project Cerebellum TAIM (Govern, Map, Measure, or Manage as fits the incident), you can help establish guardrails for AI that promote safe and secure practices.

Matched TAIM controls

Suggested mapping from embedding similarity (not a formal assessment). Browse all TAIM controls

Alleged deployer
unknown-developer-of-noodlophile-stealer, unknown-actors-operating-fraudulent-ai-themed-websites, unknown-actors-distributing-malware-as-a-service-(maas)
Alleged developer
unknown-developer-of-noodlophile-stealer
Alleged harmed parties
users-whose-devices-were-potentially-compromised-via-remote-access-trojans-(rats), targets-of-credential-theft, small-businesses-targeted-by-noodlophile-stealer, individuals-targeted-by-noodlophile-stealer

Source

Data from the AI Incident Database (AIID). Cite this incident: https://incidentdatabase.ai/cite/1080

Data source

Incident data is from the AI Incident Database (AIID).

When citing the database as a whole, please use:

McGregor, S. (2021) Preventing Repeated Real World AI Failures by Cataloging Incidents: The AI Incident Database. In Proceedings of the Thirty-Third Annual Conference on Innovative Applications of Artificial Intelligence (IAAI-21). Virtual Conference.

Pre-print on arXiv · Database snapshots & citation guide

We use weekly snapshots of the AIID for stable reference. For the official suggested citation of a specific incident, use the “Cite this incident” link on each incident page.