logo

TamperedChef Hacking Campaign Leverages Common Apps to Deliver Payloads and Gain Remote Access

ID: a76fd01b-f127-5798-ac61-ab5aa7d0ca2a

STIX ID: report--a76fd01b-f127-5798-ac61-ab5aa7d0ca2a

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-11-20

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

TamperedChef is an industrial-scale campaign that lures users to malicious, EV-signed fake installers (masquerading as manual readers, PDF editors, games, etc.) distributed via malvertising and search-engine manipulation; the installers drop an XML defining a scheduled task which executes a heavily obfuscated JavaScript backdoor that encrypts communications (XOR + base64), fingerprints machines, and supports remote code execution. Operators use U.S.-registered shell companies to acquire and rotate Extended Validation code-signing certificates, enabling persistence and rapid infrastructure recovery after takedowns; the campaign primarily affects U.S. victims, concentrated in healthcare, construction, and manufacturing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.