{"id":6899,"date":"2025-09-13T10:03:58","date_gmt":"2025-09-13T10:03:58","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/13\/evilai-as-ai-enhanced-tools-to-exfiltrate-sensitive-browser-data-and-evade-detections\/"},"modified":"2025-09-13T10:03:58","modified_gmt":"2025-09-13T10:03:58","slug":"evilai-as-ai-enhanced-tools-to-exfiltrate-sensitive-browser-data-and-evade-detections","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/13\/evilai-as-ai-enhanced-tools-to-exfiltrate-sensitive-browser-data-and-evade-detections\/","title":{"rendered":"EvilAI as AI-enhanced Tools to Exfiltrate Sensitive Browser Data and Evade Detections"},"content":{"rendered":"<p>    EvilAI as AI-enhanced Tools to Exfiltrate Sensitive Browser Data and Evade Detections<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated malware campaign has emerged that leverages artificial intelligence to create deceptively legitimate applications, marking a significant evolution in cyberthreat tactics.<\/p>\n<p>The EvilAI malware family represents a new breed of threats that combines AI-generated code with traditional trojan techniques to infiltrate systems worldwide while maintaining an unprecedented level of stealth.<\/p>\n<p>The malware operates by disguising itself as productivity and AI-enhanced tools, complete with professional interfaces, valid digital signatures, and functional features that align with their advertised purposes.<\/p>\n<p>Applications such as \u201cRecipe Lister,\u201d \u201cManual Finder,\u201d and \u201cPDF Editor\u201d provide genuine utility to users while simultaneously executing malicious payloads in the background.<\/p>\n<p>This dual-purpose approach significantly reduces user suspicion and allows the malware to establish persistence before detection.<\/p>\n<p>Global telemetry data reveals the campaign\u2019s extensive reach, with infections spanning multiple continents and affecting critical sectors including manufacturing, government services, and healthcare.<\/p>\n<p>Europe has reported the highest concentration of cases with 56 incidents, followed by the Americas and AMEA regions with 29 cases each.<\/p>\n<p>The rapid geographic distribution within just one week of monitoring indicates an active and expanding threat landscape.<\/p>\n<p>Trend Micro researchers identified that EvilAI employs sophisticated social engineering tactics combined with AI-generated code that appears clean and legitimate to static analysis tools.<\/p>\n<p>The threat actors create entirely novel applications rather than mimicking existing software brands, making detection considerably more challenging for traditional security solutions.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-advanced-infection-and-persistence-mechanisms\"><strong>Advanced Infection and Persistence Mechanisms<\/strong><\/h2>\n<p>The malware\u2019s infection chain begins when users launch seemingly legitimate applications, triggering a covert Node.js execution process that remains hidden from user visibility.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg1z8n1_HfaQzcSIZ9SpWHvMwE8uI8G6cUa5o3rUSWaFgzKltxnXVtME4hzr_am9ww-KAHMic1S1gY-f7_x32xTj7rtgary0o2TsaJb-v3wN6ZKMdQLlHUF7dWlCrXhGWcvXacnn3hKLqBeuVgqx-eKnhigSmC29Bc2sFzSvOmVViDLwH5WBPBjRMc9lNI\/s16000\/EvilAI%25E2%2580%2599s%2520observed%2520infection%2520flow%2520%28SOurce%2520-%2520Trend%2520Micro%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">EvilAI\u2019s observed infection flow (Source \u2013 Trend Micro)<\/figcaption><\/figure>\n<\/div>\n<p>The attack leverages a carefully orchestrated command sequence that silently launches node.exe via Windows command line, executing JavaScript payloads stored in temporary directories.<\/p>\n<p>The persistence mechanism demonstrates remarkable sophistication through multiple redundant methods.<\/p>\n<p>EvilAI creates scheduled tasks named \u201csys_component_health_{UID}\u201d that masquerade as legitimate Windows processes, triggering daily at 10:51 AM and repeating every four hours. The implementation uses the following command structure:<\/p>\n<pre class=\"wp-block-code\"><code>schtasks \/Create \/TN \"sys_component_health_{UID}\" \/TR \"\"C:Windowssystem32cmd[.]exe\" \/c start \"\" \/min \"%^LOCALAPPDATA^%Programsnodejsnode[.]exe\" \"%^LOCALAPPDATA^%TEMP{UID}or[.]js\"\" \/SC DAILY \/ST 10:51 \/RI 240 \/DU 24:00 \/F<\/code><\/pre>\n<p>Additionally, the malware establishes registry entries in the Windows Run key, ensuring execution at user logon while creating Start Menu shortcuts to maintain the illusion of legitimate software installation.<\/p>\n<p>The JavaScript files consistently follow naming patterns with GUID suffixes ending in characters such as \u201cor,\u201d \u201cro,\u201d or \u201cof.\u201d<\/p>\n<p>EvilAI\u2019s detection evasion capabilities extend beyond traditional obfuscation through the implementation of anti-analysis loops using MurmurHash3 32-bit hashing.<\/p>\n<p>These loops create the appearance of potentially infinite execution cycles to static analysis tools while actually executing only once, effectively forcing analysts to rely on dynamic analysis methods rather than static code examination.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/evilai-as-ai-enhanced-tools\/\">EvilAI as AI-enhanced Tools to Exfiltrate Sensitive Browser Data and Evade Detections<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/evilai-as-ai-enhanced-tools\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>EvilAI as AI-enhanced Tools to Exfiltrate Sensitive Browser Data and Evade Detections A sophisticated malware campaign has emerged that leverages artificial intelligence to create deceptively legitimate applications, marking a significant evolution in cyberthreat tactics. The EvilAI malware family represents a new breed of threats that combines AI-generated code with traditional trojan techniques to infiltrate systems [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6899","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6899"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6899"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6899\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6899"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6899"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6899"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}