EvilAI Operators Use AI-Generated Code and Fake Apps for Far-Reaching Attacks
ID: 7b01cb87-8b11-5fb4-822b-451c8df356f7
STIX ID: report--7b01cb87-8b11-5fb4-822b-451c8df356f7
Feed Name: TrendAI Security Blog
### Executive summary TrendAI Research identifies a new global malware campaign dubbed "EvilAI" that lures victims with convincing, signed, AI-like applications and executes Node.js-based JavaScript payloads to establish persistence (scheduled tasks, Start Menu shortcuts, Run registry entries), enumerate/terminate browsers and security software, exfiltrate browser credential files, and communicate with encrypted C2 (AES-256-CBC). Detections span multiple regions, countries, and critical industries, and the malware is assessed as a stager likely deploying follow-on infostealer payloads; defenders are urged to use trusted sources, layered detection (behavioral/AI), monitoring for unusual tasks/registry changes, and credential rotation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
