EvilAI is a malware distribution and fake-application campaign centered on trojanized utility software, especially PDF readers, PDF converters, file-conversion tools, and related desktop applications. The operation has been associated with a broad ecosystem of lookalike brands and variants, including PDFly, Ziply, PDFClick, Rapidoc, GalacticPDF, GFileViewer, and NovaViewer, and has also been linked in reporting to YAPA- and TamperedChef-style updater components. The actor disguises malicious software as legitimate applications, uses social engineering and advertising-driven distribution, and has been described as using AI-generated code in support of its operations. Observed EvilAI-linked applications have used multiple implementation stacks, including Inno Setup, Electron, .NET, Python compiled with customized PyInstaller packaging, and Rust-based Windows executables. Some variants provide genuine user-facing functionality, such as PDF rendering through bundled components, while covertly performing malicious actions in parallel. Reported behaviors include credential theft, persistence, downloader functionality, browser profiling, encoded telemetry collection, search hijacking, and follow-on payload delivery controlled by server-side logic after the client checks in. Certain samples have shown customized packing and obfuscation, including modified PyInstaller-style archives, in-memory loading of Python components, compressed embedded resources, and encoded network traffic. The campaign appears operationally flexible and globally oriented rather than tied to a single narrowly defined victim set. Reporting describes organizations worldwide as affected. High-confidence technical observations support capabilities in initial access through fake apps, credential theft, persistence, defense evasion through obfuscation and masquerading, reconnaissance via browser profiling and telemetry collection, and post-exploitation through updater or downloader components. EvilAI is best characterized as a financially motivated cybercriminal operation focused on deceptive software distribution and user-driven malware installation rather than a confirmed nation-state intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cluster associated with trojanized PDF/ZIP/file-converter applications such as PDFly, Ziply, PDFClick, and Rapidoc, including updater components with downloader capability and server-directed behavior.
Named operator set referenced as conducting attacks leveraging AI-generated code and fake applications.
Conducting a broad malware campaign leveraging AI-generated code and social engineering, distributing fake/masqueraded applications to bypass defenses, steal credentials, and maintain persistent access across organizations worldwide.
Referenced as a named activity cluster associated with deceptive PDF reader/converter applications and ad-driven campaigns that appear to include telemetry collection, browser profiling, and search hijacking behavior.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.