#TamperedChef
Threat actors have been using multiple websites promoted through Google ads to distribute a convincing PDF editing app that delivers an info-stealing malware called TamperedChef.
TamperedChef infostealer delivered through fraudulent PDF Editor
Threat actors have been using multiple websites promoted through Google ads to distribute a convincing PDF editing app that delivers an info-stealing malware called TamperedChef.
www.bleepingcomputer.com
August 30, 2025 at 4:23 PM
TamperedChef operates with an industrialized and business-like infrastructure, relying on a network of U.S.-registered shell companies to acquire and rotate code-signing certificates.
www.acronis.com/en/tru/posts...
Cooking up trouble: How TamperedChef uses signed apps to deliver stealthy payloads
Acronis Threat Research Unit (TRU) observed a global malvertising / SEO campaign, tracked as “TamperedChef.” It delivers legitimate-looking installers that disguise as common applications to trick use...
www.acronis.com
November 21, 2025 at 7:12 PM
These PDF editors are functional but each contain a backdoor

➡️https://virustotal.com/gui/file/fde67ba523b2c1e517d679ad4eaf87925c6bbf2f171b9212462dc9a855faa34b
bazaar.abuse.ch/sample/17355...

URLs
pdfreplace(dot)com
pdfmeta(dot)com
pdfartisan(dot)com
appsuites(dot)ai

#TamperedChef
August 20, 2025 at 3:15 PM
TamperedChef: la fabbrica degli avvelenatori di certificati digitali
il blog: insicurezzadigitale.com/tamperedchef...

#cybersecurity #malware #spyware #trojan
November 21, 2025 at 4:00 PM
-Malware reports on MonetaStealer, SolyxImmortal, TamperedChef, Remcos RAT
-New PDFSIDER APT malware
-APT-C-06 (DarkHotel) adopts USB malware
-CodeBreach vuln impacts AWS
-Cisco patches zero-day
-New 0-click Android exploit
-New FortiSIEM attacks
-CrowdStrike wins shareholder lawsuit
January 19, 2026 at 12:01 AM
TamperedChef Malvertising Campaign Drops Malware via Fake PDF Manuals - Infosecurity Magazine www.infosecurity-magazine.com/news/tampere...
TamperedChef Malvertising Campaign Drops Malware via Fake PDF Manuals
TamperedChef creates backdoors and steals user credentials – particularly in organizations reliant on technical equipment
www.infosecurity-magazine.com
January 18, 2026 at 9:37 AM
TamperedChef infostealer delivered through fraudulent PDF Editor 🔥🕵️‍♂️🧱💼

Threat actors have been using multiple websites promoted through #Google ads to distribute a convincing #PDF editing #app that delivers an #info-stealing #malware called #TamperedChef!👋

www.bleepingcomputer.com/news/securit...
TamperedChef infostealer delivered through fraudulent PDF Editor
Threat actors have been using multiple websites promoted through Google ads to distribute a convincing PDF editing app that delivers an info-stealing malware called TamperedChef.
www.bleepingcomputer.com
August 30, 2025 at 9:01 PM
-Malware reports on TamperedChef, Oyster, HeartCrypt, Lockbit 5.0, Antidot, Acreed, Amatera, DarkCloud, XWorm RAT
-GitLab security updates
-MAX app audit doesn't discover much
-Unitree secretly collects data without telling robot owners
-RomHack and UniCon videos
-Loads of new tools
September 29, 2025 at 8:18 AM
Beware of TamperedChef malware hiding in signed productivity apps! It steals data and grants remote access. Always verify software sources and stay updated. #CyberSecurity #MalwareAlert #TamperedChef Link: thedailytechfeed.com/tamperedchef...
May 22, 2026 at 2:17 PM
-Russia may ban offsec information
-Another SMS blaster detained in Vietnam
-Safetrac spied on work-from-home employees
-New BABYLONGROUP DPRK worker group
-New Mastodon phishing campaign
-Cisco ASA reconnaissance campaign
-New AI Waifu RAT, TinkyWinkey Keylogger, and TamperedChef infostealer
September 1, 2025 at 12:44 PM
TamperedChef Malware Disguised as Fake PDF Editors Steals Credentials and Cookies
TamperedChef Malware Disguised as Fake PDF Editors Steals Credentials and Cookies
thehackernews.com
August 29, 2025 at 5:45 AM
TamperedChef infostealer delivered through fraudulent PDF Editor
TamperedChef infostealer delivered through fraudulent PDF Editor
Threat actors have been using multiple websites promoted through Google ads to distribute a convincing PDF editing app that delivers an info-stealing malware called TamperedChef.
www.bleepingcomputer.com
August 30, 2025 at 4:45 PM
New TamperedChef Attack With Weaponized PDF Editor Steals Sensitive Data and Login Credentials
New TamperedChef Attack With Weaponized PDF Editor Steals Sensitive Data and Login Credentials
cybersecuritynews.com
August 28, 2025 at 2:16 PM
WithSecure STINGR reports on TamperedChef, a malvertising campaign targeting European organizations that delivers a fake PDF editor, which runs normally for weeks before activating to steal browser credentials. labs.withsecure.com/publications...
October 6, 2025 at 9:34 AM
TamperedChef sfrutta app firmate con certificati EV e malvertising per consegnare payload stealth in JavaScript e garantire accesso remoto persistente.

#Acronis #malvertising #Payload #SEO #TamperedChef
www.matricedigitale.it/2025/11/20/t...
November 20, 2025 at 9:32 AM
Palo Alto Networks documents novel activity clusters that have significant overlap with TamperedChef (aka EvilAI). TamperedChef-style malware is trojanized productivity software, such as PDF editors or calendars, that delivers malicious payloads. unit42.paloaltonetworks.com/tracking-tam...
May 21, 2026 at 8:58 AM
TamperedChef Malware Rises: Deceptive Apps Use Signed Binaries and SEO Poisoning to Hijack Browsers
TamperedChef Malware Rises: Deceptive Apps Use Signed Binaries and SEO Poisoning to Hijack Browsers
securityonline.info
September 29, 2025 at 5:48 AM
TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
November 20, 2025 at 5:39 AM
TamperedChef Malware Uses Signed Productivity Apps to Deliver Stealers and RATs
TamperedChef Malware Uses Signed Productivity Apps to Deliver Stealers and RATs
A new wave of malware disguised as everyday productivity tools has been quietly spreading across the internet, stealing user credentials and giving attackers remote control of infected systems. Researchers have tracked hundreds of campaigns tied to a threat known as TamperedChef, also called EvilAI, which wraps dangerous code inside apps that look and feel completely legitimate. Since early 2023, attackers have packaged malware inside tools like PDF editors, calendar apps, ZIP extractors, and GIF image makers. These apps work as advertised, which is exactly why victims rarely suspect anything at all. They sit silently on a device for weeks or even months before triggering malicious activity, making them difficult to catch with standard security tools. Analysts at Unit42 identified and tracked three distinct clusters of this activity, labeled CL-CRI-1089, CL-UNK-1090, and CL-UNK-1110. According to Unit42 report  shared with Cyber Security News (CSN), researchers found over 4,000 unique samples and more than 100 unique variants across these campaigns, with infections appearing in more than 50% of monitored enterprise environments globally. What makes TamperedChef so dangerous is how convincingly it mimics real software. Download pages are professionally built with legal terms, contact pages, and one-click download buttons on legitimate-looking domains. TamperedChef Malware Uses Signed Productivity Apps The apps deliver on their promises, leaving victims with little reason to question what they just installed. The scale of this operation points to a well-funded, highly organized effort. Researchers estimate the operators behind just one cluster spent over $10,000 on code-signing certificates alone, which are digital stamps that make software appear trustworthy. This level of investment signals a long-term, profit-driven campaign far beyond what typical adware operations would attempt. One of TamperedChef’s defining tactics is using legitimate code-signing certificates to make its payloads appear safe. These certificates are issued to verified companies, and most security tools treat signed software as trustworthy. Threat actors exploited this by building networks of shell companies across Ukraine, Malaysia, Israel, the UK, and the US to obtain valid certificates. Researchers traced the CL-CRI-1089 cluster to 34 unique code-signing entities, connected through shared certificate usage, overlapping code, and corporate structure analysis. The Calendaromatic campaign used a self-extracting archive containing a functional calendar app bundled with a hidden remote access Trojan. Once active, that RAT contacted a command-and-control server and pulled down a second-stage payload to further compromise the victim. The CL-UNK-1090 cluster took a more integrated approach, with the same group owning both the advertising agencies and the malware-signing companies. Examples of download pages for TamperedChef-style fake productivity applications (Source – Unit42) Over 20,000 unique ads were traced to this cluster through ad transparency platforms, spanning campaigns like CrystalPDF, OneZip, and Easy2Convert. Operators used generative AI to build distribution websites at scale, producing pages that looked similar but had structurally different underlying code. Stealers, RATs, and What Happens After Infection Once a TamperedChef app activates, it delivers one of two payload categories depending on the campaign. The first is adware and browser hijackers, which redirect searches and take control of browsing behavior. Simplified signature flow of reuse between samples (Source – Unit42) The second, and more serious, is the deployment of information stealers and remote access Trojans that target saved credentials and allow attackers to run commands remotely. Second-stage payloads typically arrive weeks after installation through an upstream API connection, long after any initial suspicion fades. In some campaigns, such as AppSuite, researchers also found proxy-style malware routing traffic through victim machines. The CL-CRI-1089 cluster showed the most aggressive credential theft, while CL-UNK-1090 favored stealthier in-memory payloads leaving fewer traces on disk. To defend against this threat, security teams should ensure endpoint detection tools are fully updated across all devices and consider enterprise browsers that block malicious downloads before they reach users. Training employees to recognize unfamiliar software risks is equally critical, even when download sites look entirely professional. If an infection is discovered, teams should quarantine related files, remove persistence mechanisms like scheduled tasks, reset credentials for affected accounts, and review access logs to confirm whether stolen credentials have already been misused. Indicators of Compromise (IoCs):- Type Indicator Description SHA256 Hash 248de1470771904462c91f146074e49b3d7416844ec143ade53f4ac0487fdb4 RapiDoc binary containing PDB path, linked to CANDY TECH LTD (CL-UNK-1090) SHA256 Hash 42231bfa7c7bd4a8ff12568074f83de8e4ec95c226230cccc6616a1a4416de268 RapiDoc binary containing PDB path, linked to CANDY TECH LTD (CL-UNK-1090) PDB Path D:!Work\Clients\<user>\Projects\RapiDoc\SrcForTests\RapiDoc\x64\Release\RapiDoc\RapiDoc.pdb Program database path found in RapiDoc binaries, likely left by mistake during build Domain onezipapp[.]com Distribution site for OneZip malware, signed by TAU CENTAURI LTD (CL-UNK-1090) Domain crystalpdf[.]com Distribution site for CrystalPDF, used by CL-UNK-1090 cluster Domain Pattern pixel.toolname[.]com C2 domain pattern used by PixelCheck variant (PDFPrime/ManualzPDF campaigns, CL-CRI-1089) Code Signer CROWN SKY LLC Code-signing entity used in Calendaromatic campaign (CL-CRI-1089) Code Signer MARKET FUSION INNOVATIONS LLC Code-signing entity linked to Calendaromatic campaign (CL-CRI-1089) Code Signer CANDY TECH LTD Core signing and advertising entity for CL-UNK-1090 cluster Code Signer TAU CENTAURI LTD Signing entity linked to OneZip campaign (CL-UNK-1090) Code Signer B.L.A ASPIRE LTD Signing entity for JustConvertFiles binaries (CL-UNK-1090) Code Signer PASTEL CONCEPTION LTD Signing entity for JustConvertFiles; linked to PDFPilot, SwiftNav, ShinyPDF, FileEase Code Signer BUZZ BOOST ADVERTISERS LLC Certificate entity linked to PixelCheck variant (CL-CRI-1089) Code Signer ADSMARKETO LLC Certificate entity linked to PixelCheck variant (CL-CRI-1089) Code Signer ADVANTAGE WEB MARKETING LLC Certificate entity linked to PixelCheck variant (CL-CRI-1089) Code Signer Europae-Solutio Ltd Certificate entity linked to PixelCheck variant (CL-CRI-1089) Code Signer SP Development and Solution Limited Certificate entity linked to PixelCheck variant (CL-CRI-1089) Code Signer LLC MATCH-TWO-USERS Certificate entity linked to PixelCheck variant (CL-CRI-1089) Code Signer Monetize forward LLC Certificate entity linked to PixelCheck variant (CL-CRI-1089) Malware Sample calendaromatic-win_x64.exe First-stage binary from Calendaromatic campaign (CL-CRI-1089) Malware Sample resources.neu Obfuscated NeutralinoJS resource file containing C2 logic, Calendaromatic campaign File Name RapiDoc.pdb Debug symbol file found in RapiDoc binaries (CL-UNK-1090) Campaign Name AppSuite PDF Malicious PDF editor spreading TamperedChef malware; observed deploying proxy-style payloads Campaign Name Calendaromatic Calendar app trojan; earliest tracked CL-CRI-1089 activity (late 2023) Campaign Name CrystalPDF Malicious PDF tool distributed by CL-UNK-1090; hosted at crystalpdf[.]com Campaign Name JustAskJacky App distributed by CL-UNK-1110 cluster Campaign Name OneZip Malicious ZIP tool signed by TAU CENTAURI LTD; distributed via onezipapp[.]com Campaign Name PDFPrime / ManualzPDF Early CL-CRI-1089 campaigns sharing code and C2 patterns (PixelCheck variant) Campaign Name ZipMakerPro TamperedChef-style app linked to CANDY TECH LTD (CL-UNK-1090) Campaign Name GifsMakerPro TamperedChef-style app linked to CANDY TECH LTD (CL-UNK-1090) Campaign Name ScreensRecorder TamperedChef-style app linked to CANDY TECH LTD (CL-UNK-1090) Campaign Name RapiDoc App with CANDY TECH LTD copyright; contained leaked PDB path (CL-UNK-1090) Campaign Name JustConvertFiles Malicious file conversion tool distributed by CANDY TECH LTD (CL-UNK-1090) Campaign Name PDFPilot Campaign linked to B.L.A ASPIRE LTD and PASTEL CONCEPTION LTD (CL-UNK-1090) Campaign Name SwiftNav Campaign linked to B.L.A ASPIRE LTD and PASTEL CONCEPTION LTD (CL-UNK-1090) Campaign Name ShinyPDF Campaign linked to B.L.A ASPIRE LTD and PASTEL CONCEPTION LTD (CL-UNK-1090) Campaign Name FileEase Campaign linked to B.L.A ASPIRE LTD and PASTEL CONCEPTION LTD (CL-UNK-109 Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post TamperedChef Malware Uses Signed Productivity Apps to Deliver Stealers and RATs appeared first on Cyber Security News .
cybersecuritynews.com
May 21, 2026 at 8:23 PM
The Acronis TRU team look into a TamperedChef malvertising/SEO campaign delivering installers disguised as common applications to trick users into installing them, which establish persistence & deliver obfuscated JavaScript payloads for remote access & control. www.acronis.com/en/tru/posts...
November 21, 2025 at 9:52 AM
TamperedChef malware is spreading through fake installers delivered via SEO poisoning + malicious ads. Signed using certificates from shell companies, these apps deploy a JavaScript backdoor to steal data and maintain persistence.
Seeing more of these installer-based attacks lately?

#CyberSecurity
November 20, 2025 at 5:01 PM
TamperedChefのマルバタイジング・キャンペーン、偽のPDFマニュアルを介してマルウェアを配布

長期間にわたるマルバタイジング・キャンペーンが、トロイの木馬化されたPDF文書を通じて、世界中の組織のネットワークにバックドア型マルウェアを投下しています。 TamperedChefと名付けられたこのマルバタイジング・キャンペーンは以前から特定されていましたが、Sophosの研究者は、標的化が欧州全域に広がっていることを詳述しました。最も一般的な被害者はドイツ、英国、フランスの組織です。…
TamperedChefのマルバタイジング・キャンペーン、偽のPDFマニュアルを介してマルウェアを配布
長期間にわたるマルバタイジング・キャンペーンが、トロイの木馬化されたPDF文書を通じて、世界中の組織のネットワークにバックドア型マルウェアを投下しています。 TamperedChefと名付けられたこのマルバタイジング・キャンペーンは以前から特定されていましたが、Sophosの研究者は、標的化が欧州全域に広がっていることを詳述しました。最も一般的な被害者はドイツ、英国、フランスの組織です。 このキャンペーンは幅広い業界の組織に感染させていますが、研究者は、専門的な技術機器に大きく依存する組織がしばしば被害を受けている点を指摘しました。こうした組織では、利用者が取扱説明書を参照したり検索したりすることが多いと考えられます。 TamperedChefはまさにこの行動を悪用し、認証情報の窃取とネットワークへのバックドアアクセスに焦点を当てたインフォスティーラーで組織に感染させています。 このキャンペーンは検知を回避するよう設計されており、ネットワーク上での永続性を確保するため、マルウェアの展開に遅延を設けています。 「この大規模で多層的な配布ネットワークには、遅延起動/休眠期間、デコイソフトウェア、段階的なペイロード配信、段階的なペイロード配信、コード署名証明書の悪用、エンドポイント保護機構を回避する取り組みなど、複数の高度な戦術が含まれていました」とSophosは述べています。 TamperedChefの攻撃チェーンの詳細 攻撃チェーンは、誰かが検索エンジンを使って何かを探すところから始まります。特に、家電のマニュアルやPDF編集ソフトに関するクエリが狙われます。 このキャンペーンの一環として、攻撃者は関連する検索結果の最上部に表示される悪意ある広告を作成しています。SEO、有料プロモーション、またはその両方によって表示されます。狙いは単純です。広告がページの最上部にあり、ユーザーが探しているものが含まれていそうに見えれば、ユーザーはそれをクリックします。 これらの広告は、ユーザーを悪意あるサイトへ誘導し、ファイルのダウンロードを促します。ユーザーが探している文書をダウンロードしているかのように装うのです。これがインフォスティーラーへの感染につながります。 「実行されると、インフォスティーラーはブラウザに保存されたデータを収集し、データ流出のためにコマンド&コントロール(C2)サーバーへの接続を確立し、追加のペイロードを取得し、さらにManualFinderApp.exeという追加のペイロードを取得します。このファイルは、インフォスティーラーおよびバックドアとして機能するトロイの木馬化されたアプリケーションです」とSophosは述べています。 しかし、検知(およびユーザーの疑念)を避けるため、悪意ある挙動はダウンロードから56日後まで開始されません。 「TamperedChefキャンペーンの背後にいる脅威アクターは、説得力のある悪意あるアプリケーションを作り込み、標的型広告を活用して大規模な配布を実現しました」とSophosは述べています。 TamperedChefのようなマルバタイジングのキャンペーンの被害に遭わないために、Sophosは、オンライン広告内のインストールリンクやポップアップをクリックせず、必要な文書は公式サイトからダウンロードするようユーザーに推奨しました。 組織向けには、情報セキュリティチームが適切な統制を適用し、ファイルやソフトウェアが承認済みで信頼できるソースからのみダウンロードできるようにすることが推奨されます。 また、多要素認証をアカウントに適用し、たとえパスワードが盗まれた場合でも、積極的に侵害されることから保護できるようにすべきです。 翻訳元:
blackhatnews.tokyo
January 16, 2026 at 12:20 PM