AI-Generated Code and Fake Apps Used for Far-Reaching Attacks
Sept. 12, 2025, 8:32 a.m.
Description
A new malware campaign called EvilAI is spreading globally by disguising itself as legitimate AI-enhanced productivity tools. The malware uses AI-generated code and professional interfaces to evade detection, targeting organizations across sectors like manufacturing, government, and healthcare. It exploits Node.js to execute malicious JavaScript, establishes persistence through scheduled tasks and registry modifications, and communicates with command-and-control servers using encrypted channels. EvilAI enumerates installed software, terminates browser processes, and duplicates credential data. It employs sophisticated obfuscation and anti-analysis techniques to hinder reverse engineering. The malware acts as an initial access vector, potentially deploying additional payloads. This campaign highlights how AI is being weaponized to create increasingly stealthy and adaptive malware threats.
Tags
Date
- Created: Sept. 12, 2025, 7:38 a.m.
- Published: Sept. 12, 2025, 7:38 a.m.
- Modified: Sept. 12, 2025, 8:32 a.m.
Indicators
- ce834dca38aeac100f853d79e77e3f61c12b9d4da48bb0a949d0a961bf9c0a27
- cf45ab681822d0a4f3916da00abd63774da58eb7e7be756fb6ec99c2c8cca815
- b0c321d6e2fc5d4e819cb871319c70d253c3bf6f9a9966a5d0f95600a19c0983
- ad0655b17bbdbd8a7430485a10681452be94f5e6c9c26b8f92e4fcba291c225a
- 9f369e63b773c06588331846dd247e48c4030183df191bc53d341fcc3be68851
- 49a4442e73521ecca8e56eb6dbc33f31eb7cfa5e62a499e552bcd29a29d79d8a
- 8ecd3c8c126be7128bf654456d171284f03e4f212c27e1b33f875b8907a7bc65
- 95001359fb671d0e6d97f37bd92642cc993e517d2307f373bfa9893639f1a2bc
- cb15e1ec1a472631c53378d54f2043ba57586e3a28329c9dbf40cb69d7c10d2c
- https://y2iax5.com
- https://mka3e8.com
- https://abf26u.com
- https://9mdp5f.com
- https://5b7crp.com
Additional Informations
- Construction
- Retail
- Financial Services
- Technology
- Healthcare
- Education
- Government
- Manufacturing
- British Indian Ocean Territory
- India
- Norway
- Spain
- Italy
- Canada
- France
- Germany
- United Kingdom of Great Britain and Northern Ireland
- Brazil
- United States of America