Threat Actors Leverage Google Ads to Weaponize PDF Editor with TamperedChef
ID: e734c1ef-aeed-5184-a7e0-79fbe51b0dbb
STIX ID: report--e734c1ef-aeed-5184-a7e0-79fbe51b0dbb
Feed Name: cybersecurityNews.com
Threat Score
A global malvertising campaign named TamperedChef used paid search ads and look-alike websites to distribute a trojanized PDF editor installer (AppSuite/PDF Editor) that silently established persistence, abused code-signing certificates, and — after a ~56 day dormant period — deployed an infostealer that harvested browser credentials, cookies, and autofill data from victims across at least 19 countries, with notable impact in Germany, the UK, and France.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
