In an alarming development, researchers found that so-called “Nudify” websites, which promise to digitally undress women in images, are spreading malware. These sites, which often appear under the brand name aiNude.ai, are part of a network operated by the Russian threat group Fin7. Users are prompted to download files containing trojans or infostealers.

Important findings

  • Malware distribution: Nudify websites are infected with Trojans and Infostealers.
  • Fin7 threat group: This group has been active since 2013 and has connections to various ransomware groups.
  • Legal measures: In California, lawsuits have been filed against several Nudify websites.

The Threat of Nudify Websites

Nudify websites often offer “Deepnude Generator” software that supposedly digitally undresses people in images. Users who upload their photos are prompted to download a “trial version” that actually contains malware. Silent Push researchers found that these sites frequently contain Lumma Stealer, NetSupport Remote Access Trojan and Redline Credential Stealer malware.

Fin7: A dangerous threat

Fin7, also known as Carbon Spider, Elbrus and Sangria Tempest, is a financially motivated threat group that has been active for over a decade. It is known for its involvement in various cyberattacks, including deploying ransomware such as REvil and DarkSide. The group uses SEO strategies to move its websites up search engine rankings and reach more victims.

Legal Action Against Nudify Websites

In August 2024, San Francisco City Attorney filed a lawsuit against 16 of the most famous Nudify websites. This lawsuit is based on allegations of violating laws protecting against sexual harassment and abuse. The FBI warned back in June that such deepfake images could be used as blackmail material.

Conclusion

The spread of malware through Nudify websites is a serious problem that not only jeopardises users’ privacy, but can also have legal consequences. The combination of financially motivated cybercriminals and the availability of generative AI models has led to an increase in such threats. Users should be cautious and aware of the risks associated with visiting such sites.

Sources

  • Breach Roundup: AI ‘Nudify’ Sites Serve Malware, BankInfoSecurity.