TamperedChef Malware Uses Signed Productivity Apps to Deliver Stealers and RATs
ID: 459ca60a-9d6b-5881-be92-4645521a29db
STIX ID: report--459ca60a-9d6b-5881-be92-4645521a29db
Feed Name: cybersecurityNews.com
Threat Score
**Executive Summary:** TamperedChef (also called EvilAI) is a widespread, organized malware campaign that distributes credential-stealing infostealers and remote access Trojans by packaging malicious payloads inside seemingly legitimate productivity applications; operators abused valid code-signing certificates and ad-based distribution to infect large numbers of enterprise endpoints and used delayed, stealthy second-stage payloads to avoid detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
