logo

Google Ads Exploited to Deliver TamperedChef Through Malicious PDF Editor

ID: 1daf370c-45af-5879-bea2-5bbcc209b38a

STIX ID: report--1daf370c-45af-5879-bea2-5bbcc209b38a

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-01-20

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A sophisticated malvertising campaign named TamperedChef used deceptive domains and Google Ads to distribute a trojanized AppSuite PDF Editor installer, compromising over 100 organizations and 300 systems across 19 countries. The payloads include an infostealer that extracts browser-stored credentials via DPAPI and a persistent backdoor (ManualFinderApp.exe) that communicates with identified C2 domains; actors used fraudulent code-signing certificates and a 56-day dormancy period to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.