UNC6032 exploits interest in AI tools by targeting users with fake 'AI video generator' websites.
Analyst brief
UNC6032 is a threat actor that weaponizes interest in AI tools by targeting users with fake 'AI video generator' websites. They primarily target individual users through malicious social media advertisements impersonating legitimate software. Their key TTPs include distributing Python-based infostealers and backdoors, and exfiltrating sensitive data like credentials and credit card information via the Telegram API. Defenders should warn users about suspicious links in social media ads mimicking popular AI tools, and monitor network traffic for unusual connections to the Telegram API.
UNC6032
unknown
UNC6032 is a threat actor that weaponizes interest in AI tools, specifically targeting users with fake "AI video generator" websites to distribute malware, including Python-based infostealers and backdoors. Victims are typically directed to these sites through malicious social media ads that impersonate legitimate tools. Compromises have led to the exfiltration of sensitive data, including login credentials and credit card information, via the Telegram API. Google Threat Intelligence Group assesses UNC6032 to have a Vietnam nexus.