logo

TamperedChef infostealer delivered through fraudulent PDF Editor

ID: d16455f8-78fd-55f8-bcba-4c90c3f7446c

STIX ID: report--d16455f8-78fd-55f8-bcba-4c90c3f7446c

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-08-30

Date Updated: 2026-07-18

Author: Ionut Ilascu

...
...

Security researchers report a widespread, well-orchestrated campaign distributing the TamperedChef infostealer through fraudulent AppSuite PDF Editor apps promoted by Google ads. The malware, activated via a "-fullupdate" argument, steals browser credentials and cookies using DPAPI, can execute arbitrary commands (backdoor behavior), and has been used to enroll victims as residential proxies; investigators identified 50+ deceptive domains, multiple fraudulent code-signing certificates, and provided IoCs to help defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.