EvilAI is a Windows malware family distributed through trojanized applications masquerading as legitimate AI-enhanced productivity tools, browsers, PDF utilities, and other software. The applications use polished interfaces, functional features, and in some cases valid code-signing certificates to appear trustworthy. Distribution has included imitation or newly registered software sites, malicious advertising, search-engine optimization abuse, social-media promotion, forums, and promoted download links.
EvilAI executes obfuscated JavaScript through Node.js. It employs control-flow flattening, Unicode-escaped strings, opaque variable names, self-cleaning behavior, and MurmurHash3-based anti-analysis logic. It establishes persistence through scheduled tasks and Windows Registry Run-key entries. The malware enumerates browser activity and installed security products, terminates browser processes, and copies browser-profile data associated with stored credentials. It communicates with command-and-control infrastructure through HTTP or HTTPS using AES-256-CBC-encrypted JSON data.
Its command dispatcher supports downloading and writing files, modifying the Registry, and executing arbitrary processes or commands, making EvilAI a modular stager/backdoor that can prepare compromised hosts for further payloads. A secondary infostealer component has been suspected but is not fully characterized. EvilAI has affected organizations globally, with observed targeting across manufacturing, government, healthcare, technology, retail, education, financial services, construction, non-profit, and utilities sectors. It has also been reported as a potential initial-access mechanism for ransomware operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Hosting them on newly registered websites that imitate vendor portals or tech solution pages Using malicious advertisements, SEO manipulation, and promoted download links on forums and social media Encouraging users to download tools for productivity, document handling, or AI-enhanced capabilities
The attacker utilized Windows Management Instrumentation (WMI) to determine if Microsoft Edge or Google Chrome was running on the system.
This allows me to look at the scheduled task that gets dropped, as well as the JS file, and some of the workings of this application.
The malware establishes persistence by creating a scheduled task named sys_component_health_{UID}, disguised to look like a legitimate Windows process.
This routine serves as EvilAI’s primary mechanism for executing arbitrary system commands, scripts, or additional malicious payloads, providing full remote command execution capabilities under the control of the C&C server.
powershell.exe "Get-WmiObject Win32_Process | Where-Object { $_.Name -eq 'chrome.exe' }"
This allows me to look at the scheduled task that gets dropped, as well as the JS file, and some of the workings of this application.
The malware establishes persistence by creating a scheduled task named sys_component_health_{UID}, disguised to look like a legitimate Windows process.
This allows me to look at the scheduled task that gets dropped, as well as the JS file, and some of the workings of this application.
The malware employs multiple layers of code obfuscation to hinder analysis and evade detection, primarily through control flow flattening.
The deobfuscated JS, ends with an EVAL, which will run any JS returned from the server after the check-in runs.
A common and highly effective evasion tactic used by EvilAI is making malicious software appear legitimate at every level.
the deletion routine constructs paths and executes reg delete via spawnSync with the /f force flag, removing specified values while returning status codes to indicate success or failure, enabling the malware to perform cleanup or anti-forensics operations on the system
The registry operations dispatcher processes arrays of commands received from the C&C server... routing commands based on the Action field (3 for add, 4 for delete).
return (await _0x324dc7(_0x26c49f.HKLM, "Software\\Microsoft\\Cryptography", "MachineGuid")).value;
the attacker utilized Windows Management Instrumentation (WMI) to determine if Microsoft Edge or Google Chrome was running on the system
Get-WmiObject Win32_Process | Where-Object { $_.Name -eq 'chrome.exe' }
the attacker performed a series of registry queries to enumerate installed software
The processor expands Windows environment variables ... and writes the resulting binary content to the specified path
Once commands are decrypted, the malware executes them, reports the results back to the C&C via HTTPS POST, and continues the cycle to maintain ongoing control.
It processes arrays of download command objects... and calls the low-level helper for each download to retrieve files from remote URLs and save them locally.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Node.js-based malware family disguised as legitimate software and fake AI/productivity tools. It acts primarily as a stager/backdoor: launches hidden JavaScript via node.exe, establishes persistence through scheduled tasks and Run keys, enumerates browsers and security software, copies browser profile data associated with credential theft, communicates with C2 over HTTP/HTTPS using AES-256-CBC-encrypted payloads, and can download files, write files, modify the registry, and execute arbitrary commands.
Malware disguised as fake AI productivity applications and used to provide ransomware actors with initial access.
Malware delivered via trojanized/masqueraded AI or productivity tools to infiltrate organizations across multiple regions.
Malware distributed as apparently legitimate AI productivity software, sometimes with valid digital signatures. It steals browser credentials, enumerates installed security software, and communicates with C2 infrastructure over AES-encrypted channels.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.