TamperedChef malvertising campaign distributing backdoor malware through trojanized PDFs
Campaign
Summary
Hide ▲
Show ▼
The TamperedChef malvertising campaign used Google ads and more than 50 domains to push a fake AppSuite PDF Editor that later activated on August 21 to steal credentials and web cookies. Truesec said the lure appeared in VirusTotal on May 15 and was advertised from around June 26, with fraudulent code-signing certificates from at least four companies later revoked. Sophos later described TamperedChef as a long-running operation using trojanized PDF documents and fake ads for appliance manuals or PDF software, with the heaviest targeting in Germany, the UK, and France. The chain can delay malicious behavior for up to 56 days, uses staged payloads and certificate abuse to evade detection, and defenders are urged to use official download sources and multi-factor authentication.
Related Happenings
JetBrains Marketplace malicious plugin API-key theft campaign
Campaign
H score15
First: 17.06.2026 00:54
Last: 17.06.2026 00:54
Sources 1
About this happening:
A coordinated malware campaign on the JetBrains Marketplace is stealing developers' AI provider API keys through malicious plugins that pose as AI coding assistants*...
JetBrains Marketplace malicious plugin API-key theft campaign
CampaignAbout this happening: A coordinated malware campaign on the JetBrains Marketplace is stealing developers' AI provider API keys through malicious plugins that pose as AI coding assistants*...
Tycoon2FA device-code phishing campaign targeting Microsoft 365
Campaign
H score46
First: 17.05.2026 17:43
Last: 17.05.2026 17:43
Sources 1
About this happening:
The Tycoon2FA phishing operation added device-code phishing to hijack Microsoft 365 accounts, expanding its ability to steal access tokens and reach email, calendar, a...
Tycoon2FA device-code phishing campaign targeting Microsoft 365
CampaignAbout this happening: The Tycoon2FA phishing operation added device-code phishing to hijack Microsoft 365 accounts, expanding its ability to steal access tokens and reach email, calendar, a...
Fake Claude PlugX phishing campaign
Campaign
H score34
First: 13.04.2026 12:52
Last: 13.04.2026 12:52
Sources 1
About this happening:
A February phishing campaign used a fake Claude website and fake meeting invitations to deliver PlugX malware to recipients, turning a popular AI brand into a malw...
Fake Claude PlugX phishing campaign
CampaignAbout this happening: A February phishing campaign used a fake Claude website and fake meeting invitations to deliver PlugX malware to recipients, turning a popular AI brand into a malw...
Latest development: 07.05.2026 13:02
A fake Claude AI site at claude-pro[.]com distributed Claude-Pro-windows-x64.zip, which drops NOVupdate.exe, NOVupdate.exe.dat, and avk.dll to sideload DonutLoader and load the Beagle backdoor on Windows. The backdoor uses license[.]claude-pro[.]com for command-and-control over TCP 443 and/or UDP 8080, and related Beagle samples were submitted to VirusTotal between February and April this year.
VENOM closed-access PhaaS operating model limits researcher visibility
Threat Actor Meta
H score18
First: 10.04.2026 00:37
Last: 10.04.2026 00:37
Sources 1
About this happening:
VENOM is operating as a closed-access phishing-as-a-service platform, reducing researcher visibility while supporting underground credential theft. The service targets...
VENOM closed-access PhaaS operating model limits researcher visibility
Threat Actor MetaAbout this happening: VENOM is operating as a closed-access phishing-as-a-service platform, reducing researcher visibility while supporting underground credential theft. The service targets...
UNC6783 BPO compromise campaign targeting downstream companies
Campaign
H score65
First: 09.04.2026 00:46
Last: 09.04.2026 00:46
Sources 1
About this happening:
UNC6783 is an active BPO compromise campaign targeting business process outsourcers and large enterprises to reach downstream environments for extortion. The opera...
UNC6783 BPO compromise campaign targeting downstream companies
CampaignAbout this happening: UNC6783 is an active BPO compromise campaign targeting business process outsourcers and large enterprises to reach downstream environments for extortion. The opera...
Timeline
-
16.01.2026 14:05 3 articles · 6mo ago
Sophos details TamperedChef malvertising chain
Technical Analysis UpdateSophos details TamperedChef, a long-running malvertising campaign that uses trojanized PDF documents and fake ads for appliance manuals or PDF editing software to deliver infostealer and backdoor malware, with the heaviest targeting in Germany, the UK, and France. The delivery chain uses malicious search-result advertising, decoy software, staged payload delivery, abuse of code-signing certificates, and delayed activation to evade endpoint protection mechanisms, and the malware can wait 56 days after download before beginning malicious behavior. Sophos recommends using official download sources, restricting software to approved and trusted sources, and enabling multi-factor authentication to reduce credential theft and unauthorized access risk.
Show sources
- TamperedChef Malvertising Campaign Drops Malware via Fake PDF Manuals — www.infosecurity-magazine.com — 16.01.2026 14:05
- TamperedChef Malvertising Campaign Drops Malware via Fake PDF Manuals — www.infosecurity-magazine.com — 16.01.2026 14:05
- TamperedChef infostealer delivered through fraudulent PDF Editor — www.bleepingcomputer.com — 30.08.2025 19:22