Cyber Crime Campaign for AppSuite PDF Editor
ID: 26008e9b-5088-5fea-b092-e881dc70c20a
STIX ID: report--26008e9b-5088-5fea-b092-e881dc70c20a
Feed Name: WatchGuard Secplicity Blog
Threat Score
WatchGuard observed a malicious campaign distributing a weaponized 'AppSuite PDF Editor' MSI via Google ads and a phishing hosting URL. The installer (appsuite-pdf.msi) creates a Run registry persistence entry, executes the program with a --cm argument to trigger callbacks that deploy the 'Tamperedchef' information stealer and an obfuscated JavaScript payload, and includes a modified elevate.exe; MSI hashes and the hosting URL are provided as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
