logo

Threat Actors Leverage Google Ads to Weaponize PDF Editor with TamperedChef

ID: e734c1ef-aeed-5184-a7e0-79fbe51b0dbb

STIX ID: report--e734c1ef-aeed-5184-a7e0-79fbe51b0dbb

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-01-20

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A global malvertising campaign named TamperedChef used paid search ads and look-alike websites to distribute a trojanized PDF editor installer (AppSuite/PDF Editor) that silently established persistence, abused code-signing certificates, and — after a ~56 day dormant period — deployed an infostealer that harvested browser credentials, cookies, and autofill data from victims across at least 19 countries, with notable impact in Germany, the UK, and France.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.