logo

TamperedChef Malware Hides in Signed Apps to Drop Stealers and RATs

ID: 65ec0987-5023-5cac-a725-99cbf465671b

STIX ID: report--65ec0987-5023-5cac-a725-99cbf465671b

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Mayura Kathir

...
...

**Executive Summary:** TamperedChef is a global malvertising-driven campaign distributing trojanized productivity apps (PDF editors, calendar tools, file converters) that use legitimate-looking sites and code-signing certificates to evade detection, employ delayed activation and staged payloads (information stealers, RATs, proxies, adware), and have produced thousands of samples and estimated infections; the report maps clusters (e.g., CL-CRI-1089, CL-UNK-1090), lists many signer entities as IOCs, and recommends monitoring persistence, signed binaries from unknown publishers, and suspicious outbound connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.