Cooking up trouble: How TamperedChef uses signed apps to deliver stealthy payloads
ID: e9fb32dc-1770-5fab-a3d5-bf3880f3473a
STIX ID: report--e9fb32dc-1770-5fab-a3d5-bf3880f3473a
Feed Name: TRU Security by Acronis
Acronis TRU identified "TamperedChef," a global malvertising and SEO-driven campaign distributing seemingly legitimate, code-signed fake applications that install a task.xml-based scheduled task to run obfuscated JavaScript backdoors; the operators use U.S.-registered shell companies to obtain and rotate certificates, host C2 infrastructure under NameCheap privacy, and target users (notably in healthcare, construction and manufacturing) for credential/data theft, resale of access, or potential ransomware staging. The report provides detailed IoCs, ATT&CK mappings, and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
