Find notable cyber news and cases, enriched with sources, timelines, and signals.

EvilAI malware activity spreading through fake AI apps

Malware Activity
First reported
Last updated
Happening score
H score 22
2 unique sources, 3 articles

Summary

Hide ▲

EvilAI is a malware campaign that uses fake AI and productivity apps to infect organizations across the U.S., India, the U.K., Germany, France, Brazil, and other regions. Trend Micro said the lures used names such as App Suite, Epi Browser, JustAskJacky, Manual Finder, Tampered Chef, and Recipe Maker, with digital signatures and evasive behavior that included reconnaissance and attempts to disable Bitdefender, Kaspersky, and Fortinet. Later reporting tied TamperedChef to an ongoing malvertising effort using fake installers, abused code-signing certificates, and a scheduled-task-launched obfuscated JavaScript backdoor. The activity remains active, with infections concentrated in the U.S. and additional cases in Israel, Spain, Germany, India, and Ireland.

Related Happenings

Silver Fox tax-themed phishing campaign delivering ABCDoor and ValleyRAT

Campaign
H score36 First: 04.05.2026 14:57 Last: 04.05.2026 14:57 Sources 1

About this happening: Silver Fox is running a tax-themed phishing campaign that now targets India with Income Tax Department lures and delivers ValleyRAT (aka Winos 4.0). The campai...

ABCDoor backdoor activity in Silver Fox attacks

Malware Activity
H score23 First: 04.05.2026 14:35 Last: 04.05.2026 14:35 Sources 1

About this happening: The newly identified ABCDoor backdoor is being used in real-world attacks by Silver Fox, expanding the group's malware set and increasing the risk of covert remote acc...

Vidar infostealer market rise and distribution expansion

Malware Activity
H score30 First: 28.04.2026 22:07 Last: 28.04.2026 22:07 Sources 1

About this happening: Vidar remains a long-running infostealer threat, and Aryaka reported a fresh campaign in recent weeks that adds new obfuscation techniques and stronger steal...

LotusLite backdoor delivered via DLL sideloading

Malware Activity
H score22 First: 21.04.2026 15:00 Last: 21.04.2026 15:00 Sources 1

About this happening: The Mustang Panda campaign spans an April 2026 wave against India's banking sector and US-Korea policy circles and a later June 12–22, 2026 wave against Indi...

Latest development: 29.06.2026 18:03

Acronis observed Mustang Panda campaigns against Indian government and hydropower targets using SHARDLOADER, MINIRECON, and ZOHOMURK, with Zoho WorkDrive abused as a command-and-control and exfiltration channel. The activity involved spear-phishing ZIP archives, DLL sideloading through signed binaries such as Solid PDF Creator and Citrix Receiver, and active beaconing from June 12 to June 22, 2026; Acronis also found active compromises inside Indian government networks and worked with CERT-In on notification and cleanup.

TBK DVR command injection flaw actively exploited (CVE-2024-3721)

Vulnerability
H score1 First: 20.04.2026 16:01 Last: 20.04.2026 16:01 Sources 1

About this happening: The CVE-2024-3721 command injection flaw in TBK DVR systems is being actively exploited to gain access and install Nexcorium malware. Attackers abuse crafted request...

Timeline

  1. 11.09.2025 21:37 4 articles · 10mo ago

    Trend Micro discloses EvilAI malware campaign

    Initial Disclosure

    Trend Micro identifies the EvilAI malware campaign using legit-looking AI and productivity apps to infect organizations across manufacturing, government, healthcare, and other sectors in the US, India, the UK, Germany, France, Brazil, and beyond. The malicious apps use names such as App Suite, Epi Browser JustAskJacky, Manual Finder, Tampered Chef, and Recipe Maker, rely on digital signatures from newly registered entities, and are designed to evade detection while carrying out reconnaissance, terminating Microsoft Edge and Chrome, attempting to disable Bitdefender, Kaspersky, and Fortinet, and maintaining persistence through scheduled tasks, registry manipulation, obfuscation, and encrypted C2 communication as a stager for future payloads.

    Show sources