logo

Trojanized PDF Editor: “TamperedChef” Campaign Bypasses Windows SmartScreen

ID: d5608981-8c7d-56cf-a595-027166554330

STIX ID: report--d5608981-8c7d-56cf-a595-027166554330

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-20

Date Updated: 2026-04-23

Author: Ddos

...
...

TamperedChef is a malvertising campaign that promoted a trojanized "AppSuite PDF Editor" through Google Ads to deliver an infostealer to Windows machines; attackers used valid EV code-signing to evade Windows SmartScreen, Sophos X-Ops identified more than 100 infected systems across at least 19 countries (notably Germany, the UK and France), and the campaign lures users searching for manuals via metadata labeled "Manual FinderApp".

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.