EvilAI Malware Campaign Masquerading as AI Productivity Tools
Threat actors have launched a sophisticated malware campaign, dubbed EvilAI, that leverages seemingly legitimate artificial intelligence (AI) and productivity tools to infiltrate organizations worldwide. Security researchers from Trend Micro have identified that the campaign targets a broad range of sectors, including manufacturing, government, healthcare, technology, and retail. The malware is distributed through applications that appear authentic, such as AppSuite, Epi Browser, JustAskJacky, Manual Finder, OneStart, PDF Editor, Recipe Lister, and Tampered Chef. These applications are designed to function as normal software while secretly delivering malicious payloads in the background. The attackers have enhanced their deception by using code signing certificates from disposable companies, making the malicious software appear trustworthy to both users and security controls. The campaign has achieved a global reach, with infections reported in India, the United States, France, Italy, Brazil, Germany, the United Kingdom, Norway, Spain, and Canada. Researchers have noted that the rapid and widespread distribution of EvilAI indicates an active and evolving threat, rather than isolated incidents. The malware is capable of a range of nefarious activities, including data theft, system compromise, and establishing persistence within victim environments. The use of SEO poisoning and signed binaries further increases the likelihood of successful infections, as users are more likely to trust and download these applications. The Tampered Chef application, in particular, has been highlighted as one of the deceptive apps used in this campaign, employing signed binaries and SEO manipulation to hijack browsers and facilitate further compromise. Security firms such as Expel, G DATA, and TRUESEC have also documented aspects of the EvilAI campaign, underscoring its complexity and the collaboration among threat intelligence communities to track its evolution. The attackers' ability to blur the line between legitimate and malicious software poses significant challenges for traditional security defenses. Organizations are urged to exercise caution when downloading and installing AI or productivity tools, especially those from unverified sources. The campaign's technical sophistication, global impact, and use of advanced evasion techniques make it a significant concern for cybersecurity professionals. Ongoing monitoring and intelligence sharing remain critical to detecting and mitigating the threat posed by EvilAI. The campaign demonstrates the increasing trend of threat actors exploiting the popularity of AI tools to gain initial access to enterprise environments. Security teams should prioritize user education, application whitelisting, and robust endpoint protection to defend against such deceptive malware campaigns.
Jun 29, 2026