Close Menu
    X (Twitter) LinkedIn
    CapitalAI DailyCapitalAI Daily
    X (Twitter) LinkedIn
    • Markets & Investments
    • Big Tech & AI
    • AI & Cybercrime
    • Jobs & AI
    • Banks
    • Crypto
    Sunday, April 12
    CapitalAI DailyCapitalAI Daily
    Home»AI & Cybercrime»AI-Powered Malware EvilAI Steals Sensitive Google Chrome and Microsoft Edge User Data in US and Abroad, Warns Trend Micro

    AI-Powered Malware EvilAI Steals Sensitive Google Chrome and Microsoft Edge User Data in US and Abroad, Warns Trend Micro

    By Henry KanapiOctober 1, 20253 Mins Read
    Share
    Twitter LinkedIn

    A new wave of AI-powered malware is infiltrating organizations worldwide, disguised as legitimate software and carrying the potential for widespread disruption.

    Cybersecurity researchers at Trend Micro warn that the trojan, tracked as EvilAI, poses as productivity or AI-enhanced utilities with professional interfaces and valid digital signatures.

    The deception has enabled the malware to penetrate both corporate and personal systems across multiple continents. First detected in late August, EvilAI infections have already appeared in Europe, the Americas, and the AMEA region, with early telemetry showing more than 100 confirmed cases. India has reported 74 incidents, followed by the United States with 68 and France with 58.

    Source: Trend Micro

    The malware’s mechanics are rooted in mimicry. Malicious apps such as Recipe Lister and PDF Editor deliver functional features to gain trust, while simultaneously launching hidden JavaScript payloads via Node.js. Attackers further enhance credibility with stolen or newly registered code-signing certificates, making the software appear “verified” to end users.

    The scale is broad and indiscriminate, with industry telemetry showing manufacturing with 58 incidents, government services with 51, and healthcare with 48. Technology and retail sectors have also been hit, underscoring the malware’s reach.

    Trend Micro says the malware uses AES-encrypted channels to maintain real-time communication with C2 servers. Attackers can exfiltrate browser data, enumerate security tools via registry queries, and deploy additional payloads through persistent scheduled tasks that blend in with legitimate Windows processes.

    “Based on telemetry, the attacker created copies of both the ‘Web Data’ and ‘Preferences’ files from Microsoft Edge and Google Chrome browser profiles.”

    The campaign remains active and appears to be operating as a stager, establishing access for secondary infostealers that remain unidentified. Cybersecurity researchers caution that the sophistication and speed of EvilAI’s spread reflect the increasing weaponization of artificial intelligence by threat actors.

    “This lack of clarity poses a significant risk. Without knowing what’s being delivered post-infection, organizations cannot fully assess the damage or implement effective containment. It also suggests the campaign is still active and evolving, with attackers possibly testing or rotating payloads in real time.

    The rise of AI-powered malware like EvilAI underscores a broader shift in the threat landscape. AI is no longer just a tool for defenders – it’s now being weaponized by threat actors to produce malware that is smarter, stealthier, and more scalable than ever before. In this environment, familiar software, signed certificates, and polished interfaces can no longer be taken at face value.”

    Disclaimer: Opinions expressed at CapitalAI Daily are not investment advice. Investors should do their own due diligence before making any decisions involving securities, cryptocurrencies, or digital assets. Your transfers and trades are at your own risk, and any losses you may incur are your responsibility. CapitalAI Daily does not recommend the buying or selling of any assets, nor is CapitalAI Daily an investment advisor. See our Editorial Standards and Terms of Use.

    AI AI-powered malware Malware Trend Micro
    Previous ArticleJPMorgan Races Toward AI-Connected Future As Bank of America Rolls Out AI for Payments
    Next Article Arm CEO Rene Haas Names One AI Play That’s Going To Be Bigger Than Data Centers – And It’s Not Power

    Read More

    OpenAI Affected by North Korea-Linked Software Supply Chain Attack, Moves To Block Risk of Fake Apps

    April 11, 2026

    Treasury and Fed Summon Goldman Sachs, Citi, Morgan Stanley, BofA, and Wells Fargo CEOs Over Anthropic’s Mythos Cyber Risks

    April 11, 2026

    IBM Warns Anthropic’s Mythos Marks ‘Step Change’ by Linking Hidden Flaws to Full System Takeovers

    April 11, 2026

    ZachXBT Uncovers $3,500,000+ North Korean Network Using Fake Identities To Target AI and Crypto Firms

    April 10, 2026

    AI Mass Adoption? New Study Finds Half of Americans Used AI in the Past Week for Search, Writing and More

    April 10, 2026

    Jamie Dimon Flags Blockchain, Stablecoins as New Threats for JPMorgan Chase, Says AI Will Be Key To Competing

    April 10, 2026
    X (Twitter) LinkedIn
    • About
    • Author
    • Editorial Standards
    • Contact Us
    • Privacy Policy
    • Terms of Service
    • Cookie Policy
    © 2025 CapitalAI Daily. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.