logo

EvilAI Operators Use AI-Generated Code and Fake Apps for Far-Reaching Attacks

ID: 7b01cb87-8b11-5fb4-822b-451c8df356f7

STIX ID: report--7b01cb87-8b11-5fb4-822b-451c8df356f7

Feed Name: TrendAI Security Blog

Threat Score
75/100

Date Published: 2026-01-01

Date Updated: 2026-08-06

...
...

### Executive summary TrendAI Research identifies a new global malware campaign dubbed "EvilAI" that lures victims with convincing, signed, AI-like applications and executes Node.js-based JavaScript payloads to establish persistence (scheduled tasks, Start Menu shortcuts, Run registry entries), enumerate/terminate browsers and security software, exfiltrate browser credential files, and communicate with encrypted C2 (AES-256-CBC). Detections span multiple regions, countries, and critical industries, and the malware is assessed as a stager likely deploying follow-on infostealer payloads; defenders are urged to use trusted sources, layered detection (behavioral/AI), monitoring for unusual tasks/registry changes, and credential rotation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.