EvilAI malware activity spreading through fake AI apps
Malware Activity
Summary
Hide ▲
Show ▼
EvilAI is a malware campaign that uses fake AI and productivity apps to infect organizations across the U.S., India, the U.K., Germany, France, Brazil, and other regions. Trend Micro said the lures used names such as App Suite, Epi Browser, JustAskJacky, Manual Finder, Tampered Chef, and Recipe Maker, with digital signatures and evasive behavior that included reconnaissance and attempts to disable Bitdefender, Kaspersky, and Fortinet. Later reporting tied TamperedChef to an ongoing malvertising effort using fake installers, abused code-signing certificates, and a scheduled-task-launched obfuscated JavaScript backdoor. The activity remains active, with infections concentrated in the U.S. and additional cases in Israel, Spain, Germany, India, and Ireland.
Related Happenings
Silver Fox tax-themed phishing campaign delivering ABCDoor and ValleyRAT
Campaign
H score36
First: 04.05.2026 14:57
Last: 04.05.2026 14:57
Sources 1
About this happening:
Silver Fox is running a tax-themed phishing campaign that now targets India with Income Tax Department lures and delivers ValleyRAT (aka Winos 4.0). The campai...
Silver Fox tax-themed phishing campaign delivering ABCDoor and ValleyRAT
CampaignAbout this happening: Silver Fox is running a tax-themed phishing campaign that now targets India with Income Tax Department lures and delivers ValleyRAT (aka Winos 4.0). The campai...
ABCDoor backdoor activity in Silver Fox attacks
Malware Activity
H score23
First: 04.05.2026 14:35
Last: 04.05.2026 14:35
Sources 1
About this happening:
The newly identified ABCDoor backdoor is being used in real-world attacks by Silver Fox, expanding the group's malware set and increasing the risk of covert remote acc...
ABCDoor backdoor activity in Silver Fox attacks
Malware ActivityAbout this happening: The newly identified ABCDoor backdoor is being used in real-world attacks by Silver Fox, expanding the group's malware set and increasing the risk of covert remote acc...
Vidar infostealer market rise and distribution expansion
Malware Activity
H score30
First: 28.04.2026 22:07
Last: 28.04.2026 22:07
Sources 1
About this happening:
Vidar remains a long-running infostealer threat, and Aryaka reported a fresh campaign in recent weeks that adds new obfuscation techniques and stronger steal...
Vidar infostealer market rise and distribution expansion
Malware ActivityAbout this happening: Vidar remains a long-running infostealer threat, and Aryaka reported a fresh campaign in recent weeks that adds new obfuscation techniques and stronger steal...
LotusLite backdoor delivered via DLL sideloading
Malware Activity
H score22
First: 21.04.2026 15:00
Last: 21.04.2026 15:00
Sources 1
About this happening:
The Mustang Panda campaign spans an April 2026 wave against India's banking sector and US-Korea policy circles and a later June 12–22, 2026 wave against Indi...
LotusLite backdoor delivered via DLL sideloading
Malware ActivityAbout this happening: The Mustang Panda campaign spans an April 2026 wave against India's banking sector and US-Korea policy circles and a later June 12–22, 2026 wave against Indi...
Latest development: 29.06.2026 18:03
Acronis observed Mustang Panda campaigns against Indian government and hydropower targets using SHARDLOADER, MINIRECON, and ZOHOMURK, with Zoho WorkDrive abused as a command-and-control and exfiltration channel. The activity involved spear-phishing ZIP archives, DLL sideloading through signed binaries such as Solid PDF Creator and Citrix Receiver, and active beaconing from June 12 to June 22, 2026; Acronis also found active compromises inside Indian government networks and worked with CERT-In on notification and cleanup.
TBK DVR command injection flaw actively exploited (CVE-2024-3721)
Vulnerability
H score1
First: 20.04.2026 16:01
Last: 20.04.2026 16:01
Sources 1
About this happening:
The CVE-2024-3721 command injection flaw in TBK DVR systems is being actively exploited to gain access and install Nexcorium malware. Attackers abuse crafted request...
TBK DVR command injection flaw actively exploited (CVE-2024-3721)
VulnerabilityAbout this happening: The CVE-2024-3721 command injection flaw in TBK DVR systems is being actively exploited to gain access and install Nexcorium malware. Attackers abuse crafted request...
Timeline
-
11.09.2025 21:37 4 articles · 10mo ago
Trend Micro discloses EvilAI malware campaign
Initial DisclosureTrend Micro identifies the EvilAI malware campaign using legit-looking AI and productivity apps to infect organizations across manufacturing, government, healthcare, and other sectors in the US, India, the UK, Germany, France, Brazil, and beyond. The malicious apps use names such as App Suite, Epi Browser JustAskJacky, Manual Finder, Tampered Chef, and Recipe Maker, rely on digital signatures from newly registered entities, and are designed to evade detection while carrying out reconnaissance, terminating Microsoft Edge and Chrome, attempting to disable Bitdefender, Kaspersky, and Fortinet, and maintaining persistence through scheduled tasks, registry manipulation, obfuscation, and encrypted C2 communication as a stager for future payloads.
Show sources
- AI-Enhanced Malware Sports Super-Stealthy Tactics — www.darkreading.com — 11.09.2025 21:37
- AI-Enhanced Malware Sports Super-Stealthy Tactics — www.darkreading.com — 11.09.2025 21:37
- EvilAI Malware Masquerades as AI Tools to Infiltrate Global Organizations — thehackernews.com — 29.09.2025 19:36
- TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign — thehackernews.com — 20.11.2025 06:06