Fake AI Tools Deliver Malware to Developers, Granting Enterprise Access
Key Takeaways A new malware campaign, identified as part of the broader TroyDens lure factory, is exploiting developer interest in AI tools by distributing malicious downloads disguised as legitimate...
Key Takeaways
- A new malware campaign, identified as part of the broader TroyDens lure factory, is exploiting developer interest in AI tools by distributing malicious downloads disguised as legitimate GitHub projects.
- The attackers utilize cloned GitHub repositories to deliver a multi-stage information stealer, SmartLoader, which can lead to initial access into enterprise environments.
- The campaign specifically targets developers seeking AI resources, coding assistants, security guides, and AI-related frameworks, primarily impacting financial services, banking, and technology sectors across North America, Asia, and Southern Europe.
- SmartLoader employs sophisticated evasion techniques, including LuaJIT execution of obfuscated scripts and the use of a Polygon blockchain smart contract to dynamically resolve its command-and-control server, making detection and takedown more challenging.
- Compromised developer credentials or sessions pose a significant risk, potentially enabling data theft, software supply chain attacks, and broader enterprise intrusion.
A sophisticated new malware campaign is leveraging the surging interest in artificial intelligence tools to gain unauthorized access to enterprise networks. Threat actors are creating deceptive copies of popular GitHub projects, embedding malicious files within what appear to be benign downloads attractive to developers and AI enthusiasts. This tactic provides a potent pathway for initial enterprise intrusion.
Table Of Content
The campaign specifically targets individuals searching for AI resources, coding assistants, Python security guides, Rust frameworks, tools related to Claude, and ComfyUI projects. The primary victims identified thus far include organizations in the financial services, banking, and technology sectors across North America, Asia, and Southern Europe.
Netskope said in a report shared with Cyber Security News (CSN) that this malicious activity is intricately linked to the larger TroyDens lure factory, a known hub for such deceptive operations.
Researchers at Netskope discovered that the attackers employ cloned repositories to distribute a Malware-as-a-Service information stealer through a complex, two-stage SmartLoader chain. The critical nature of this campaign stems from the elevated privileges often held by developers, who typically possess access to sensitive assets such as cloud environments, proprietary source code, API keys, code-signing certificates, and CI/CD systems.
A successful compromise of a developer’s session or credentials can provide attackers with a crucial foothold within an organization, paving the way for extensive data theft or devastating software supply chain attacks.
Fake AI Tool Campaign Mechanics
The attackers meticulously craft their malicious GitHub pages to mimic legitimate repositories. This involves copying genuine code, detailed documentation, authentic-looking contributor profiles, and accurate installation instructions. This high level of verisimilitude is designed to instill a false sense of security in unsuspecting developers.
Malicious payloads are cunningly hidden within seemingly innocuous folders or integrated into altered setup procedures. This technique mirrors other observed fake GitHub repository operations that exploit user trust in code-sharing platforms.
Upon execution, victims receive a ZIP archive containing four key files: lua51.dll, compiler.exe, Application.bat, and a text file named gc.txt. The batch file initiates the renamed LuaJIT interpreter (compiler.exe), which then executes obfuscated Lua code from the gc.txt file rather than a conventional executable. This method allows the malware to circumvent basic security scans, as each component appears less suspicious in isolation. The full malicious functionality, including network requests, file writing, and process initiation, only unfolds when all parts of the archive are present and interact as intended.
The initial Lua script is protected using Prometheus obfuscation, while the second stage appears to utilize MoonSec V3. This multi-layered obfuscation strategy is consistent with previous SmartLoader campaigns that have leveraged trusted code-sharing services for distributing sophisticated, multi-stage payloads.
Blockchain Hides the Control Server
SmartLoader initiates its operations by gathering critical intelligence from the compromised machine, including the victim’s public IP address, geographical location, time zone, internet service provider, and a screenshot of the desktop. This reconnaissance data is then transmitted via an encrypted beacon to a command-and-control (C2) server, providing the attackers with sufficient information to determine their next steps for exploiting the compromised device.
A notable innovation in this campaign is the use of blockchain technology to obscure the C2 infrastructure. Instead of hardcoding a static C2 address, both stages of the loader query a Polygon smart contract at runtime. This “EtherHiding” technique grants the attackers the flexibility to update their C2 server address by modifying a blockchain value, eliminating the need to recompile or redistribute the malware. This significantly enhances the resilience and agility of the C2 infrastructure against detection and takedown efforts.
The second stage of the attack involves downloading additional Lua content and the final information-stealing payload from attacker-controlled GitHub accounts. Netskope researchers observed several variants of the infostealer, including one based on NodeJS, indicating that the SmartLoader framework is modular and can deploy different malware payloads based on the specific objectives of the operators.
What You Should Do
- Verify Project Authenticity: Before downloading or running any GitHub-hosted installers, always meticulously verify the project’s ownership, review its contributor history, and cross-reference with official release sources. Be wary of newly created repositories or those with minimal activity.
- Monitor Unusual Network Traffic: Implement robust network monitoring to detect unusual blockchain RPC traffic originating from script interpreters, batch files, or user-writable folders. This can be an early indicator of compromise, especially given the use of Polygon smart contracts for C2 resolution.
- Implement Application Controls: Utilize application whitelisting and other controls to restrict the execution of unsigned interpreters and script launchers, particularly outside of approved, secure directories.
- Enhance Endpoint Monitoring: Actively monitor for suspicious activities such as the creation of unscheduled tasks, direct downloads from raw GitHub links, web requests to bare IP addresses, and unexpected screenshot captures. These are common behaviors exhibited by the SmartLoader.
- Educate Developers: Conduct regular cybersecurity awareness training for development teams, emphasizing the risks associated with downloading untrusted code and the importance of supply chain security best practices.
- Review IoCs: Integrate the provided Indicators of Compromise (IoCs) into your threat intelligence platforms (e.g., MISP, VirusTotal) and SIEM systems for proactive detection and blocking. Remember to re-fang any defanged indicators within your controlled environments.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| URL | http://ip-api.com/json |
Geolocation service queried by SmartLoader. <a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e36aae40-80b3-4672-b66e-aa84603967da/Fake-AI-Tool-Campaign-Turns-Developer-Interest-Into-Enterprise-Initial-Access.pdf?AWSAccessKeyId=ASIA2F3EMEYEYXK3U5FK&Signature=wQ0tSPUV1G2rWtjHLmFnS80subo%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEEEaCXVzLWVhc3QtMSJHMEUCIQC1Pq%2BN5apgvz56BD2Qz97BFAu1pAAlHajXx6c5E5Xk3AIgcC0yREcqbeRXtExW4BJUN3Y1KysGdjnk7nUwvQNc3yEq8wQICRABGgw2OTk3NTMzMDk3MDUiDD%2FTJHdiLgMBy1WyISrQBEiKaVEJ27LzOzgaBWWhIPUF7gfWGg4ADPnEGU%2BQ1qdwyUmZ9KgdPzRHWYn5gtj%2FwfHJk9zXKCqMLpuqpNFZcxrSxLSlvbHsgQ2QijRRZH5KgdpCq0c7yxSd5nbdvHL5fkBFCnw5V%2BRu1eGONEUCR%2FDnkSwQhNkYvG6%2Fi8FVcV8Ipz1c0ovCNV9sNI9beAZnfOCfvRr4dCbw%2FLXrKVsraAzgal1zoYb5UW6YFXORRgPUwMp2jySpixMppfgVOinqrEP9rK3TWn8uawUsCd0TG5TADU8VFo3VWPwatkMWiPh6q5h8OzW5cmk%2FztA6o0rgUI13lJhTX9m14PQl5C7pei5Vmmu%2FiQhMxnHsFRJEiGnXuMxr5jmNj2mrgcQ2JjSvMTG2H1k%2Fo%2B6wJs818gNxKxVqLA18HmmGvZw3M59zX8313cojA5lOBjgZkTgSu8ojkcwu7p%2F148xjexQB7g9B4PFS4LZEQj20uv1rkdee2xESKb0xXK6ENs6YaGM7nuMVpm6oubpD4WzZysuLfZDdqCF4mo70cLRPUflok8MrVYILmlgKd8UR7Kaa5SFTnFT%2BaG%2BwJz6Sb6D0QOfCyxXNuW8jQ6SAFbeUX1MhI9pmTIEgquP1KYZjBUuv9cADdNlTuq3IyDfyjiDNjWvzWZgoFr9tuobpkuv3MWEwsr9iBF1QA4Q7j4%2B6WhhDWPx164lDM9yGYQobBh2VJCOoMz7w7OJAedbqZ0Jl93Cy%2Fbd
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources. |



No Comment! Be the first one.