logo

Cyber Crime Campaign for AppSuite PDF Editor

ID: 26008e9b-5088-5fea-b092-e881dc70c20a

STIX ID: report--26008e9b-5088-5fea-b092-e881dc70c20a

Feed Name: WatchGuard Secplicity Blog

Threat Score
70/100

Date Published: 2025-08-29

Date Updated: 2026-05-01

Author: Kristen Yang

...
...

WatchGuard observed a malicious campaign distributing a weaponized 'AppSuite PDF Editor' MSI via Google ads and a phishing hosting URL. The installer (appsuite-pdf.msi) creates a Run registry persistence entry, executes the program with a --cm argument to trigger callbacks that deploy the 'Tamperedchef' information stealer and an obfuscated JavaScript payload, and includes a modified elevate.exe; MSI hashes and the hosting URL are provided as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.