logo

TamperedChef Malware Abuses Signed Productivity Apps To Deliver Stealers

ID: 28d5bb9a-43bc-5310-a4d9-5c3c0bdd3847

STIX ID: report--28d5bb9a-43bc-5310-a4d9-5c3c0bdd3847

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-21

Date Updated: 2026-05-22

Author: Varshini

...
...

TamperedChef is a large-scale malvertising campaign that lures victims to professionally faked download sites for productivity tools (AppSuite PDF, Calendaromatic, OneZip, CrystalPDF) which are trojanized and digitally signed by shell companies; once installed they use scheduled tasks and obfuscated JavaScript (including Neutralino.js) to fetch RATs, browser hijackers, and credential stealers and exfiltrate data via AES-encrypted channels, with researchers tracking over 4,000 distinct samples and multiple code-signing entities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.