TamperedChef Malware Abuses Signed Productivity Apps To Deliver Stealers
ID: 28d5bb9a-43bc-5310-a4d9-5c3c0bdd3847
STIX ID: report--28d5bb9a-43bc-5310-a4d9-5c3c0bdd3847
Feed Name: Cyber Press
TamperedChef is a large-scale malvertising campaign that lures victims to professionally faked download sites for productivity tools (AppSuite PDF, Calendaromatic, OneZip, CrystalPDF) which are trojanized and digitally signed by shell companies; once installed they use scheduled tasks and obfuscated JavaScript (including Neutralino.js) to fetch RATs, browser hijackers, and credential stealers and exfiltrate data via AES-encrypted channels, with researchers tracking over 4,000 distinct samples and multiple code-signing entities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
