Malicious Appsuite PDF Editor Spreads Tamperedchef Malware
TLP:white
AlienVault
A large cybercrime campaign has been observed involving multiple fraudulent websites promoted through Google advertising. The campaign aims to trick users into downloading and installing a trojanized PDF editor containing the TamperedChef information-stealing malware. The malware harvests sensitive data, including credentials and web cookies. The campaign began on June 26, 2025, with the PDF editor initially appearing harmless but later activating malicious capabilities. The threat actor used Google advertising to promote the PDF editor, with at least 5 different campaign IDs observed. The malware's activation occurred 56 days after the campaign's start, coinciding with a typical Google ad campaign duration. The threat actor has a history of distributing malicious code disguised as free utility tools, and this campaign has successfully affected several European organizations.
google advertising
information stealer
obfuscation
credential theft
tamperedchef
+2 more
FileHash-MD5 12
FileHash-SHA1 10
FileHash-SHA256 63
domain 30
hostname 4
Created: Aug 28, 2025 1:34 PM
Updated: Aug 28, 2025 1:36 PM