{"id":73048,"date":"2026-02-04T07:06:02","date_gmt":"2026-02-03T23:06:02","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=73048"},"modified":"2026-01-30T09:07:55","modified_gmt":"2026-01-30T01:07:55","slug":"tamperedchef-serves-bad-ads-with-infostealers-as-the-main-course","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2026\/02\/04\/tamperedchef-serves-bad-ads-with-infostealers-as-the-main-course\/","title":{"rendered":"TamperedChef serves bad ads, with infostealers as the main course"},"content":{"rendered":"<p><strong><a href=\"https:\/\/www.sophos.com\/\">Sophos<\/a>, a global leader of innovative security solutions for defeating cyberattacks, recently identified a\u00a0malvertising\u00a0campaign distributing an infostealer dubbed TamperedChef \u2013 believed to be part of a wider campaign known as\u00a0EvilAI.\u00a0<\/strong><\/p>\n<p>Previous coverage\u00a0of this campaign suggests it began on June 26, 2025, with many of the associated websites being registered or first identified on that date. The sites were promoting a trojanized PDF editing application called\u00a0AppSuite PDF Editor\u00a0via Google Ads. This application appeared legitimate to users, but silently deployed an infostealer upon installation, targeting Windows devices.<\/p>\n<p>Through telemetry analysis and threat hunting, Sophos MDR confirmed that over 100 customer systems were affected before our detection and response efforts began.<\/p>\n<p>According to Sophos telemetry, the majority of victims affected by this campaign are in Germany (~15%), the United Kingdom (~14%), and France (~9%). Although the data highlights a significant concentration in Germany and the UK, it likely reflects the campaign\u2019s widespread global reach, rather than any deliberate targeting of specific regions; we identified 19 countries affected in total.<\/p>\n<p>Victims of this campaign span a variety of industries, particularly those where operations rely heavily on specialized technical equipment \u2013 possibly because users in those industries frequently search online for product manuals, a behavior that the TamperedChef campaign exploits to distribute malicious software.<\/p>\n<p>Further investigation revealed that this large, multi-layered distribution network featured multiple advanced tactics, including a delayed activation\/dormancy period, decoy software, staged payload delivery, staged payload delivery, abuse of code-signing certificates, and efforts to evade endpoint protection mechanisms.<\/p>\n<p>According to\u00a0other researchers, the campaign appears to still be active, with new components still being uncovered and supporting infrastructure continuing to operate (although the domains we observed in our investigations now seem to be inactive).<\/p>\n<p><strong>Conclusions and recommendations<\/strong><\/p>\n<p>The threat actors behind the TamperedChef campaign crafted convincing malicious applications, leveraged targeted advertising to achieve large-scale distribution, and secured code-signing certificates. The consequences are severe; users who have installed\u00a0AppSuite PDF Editor\u00a0should consider any credentials stored in their browsers to be compromised.<\/p>\n<p>Threat actors are well aware that malvertising can be a fruitful and effective infection vector. It\u2019s very possible that the adversaries behind TamperedChef, and others, will cook from a similar recipe in the future.<\/p>\n<p><strong>Proactive recommended actions<\/strong><\/p>\n<ul>\n<li>Avoid installing software from ads:Avoid clicking installation links or pop-ups in online ads \u2014 even if they appear to come from familiar or well-known brands. Instead, obtain software only from official vendor sites<\/li>\n<li>Implement strict application controls:\u00a0In corporate settings, restrict installations to approved software only where appropriate<\/li>\n<li>Harden credential management:Disable browser-based password storage where possible and enforce the use of secure, organization-approved password managers; require MFA or passkeys for all accounts to reduce the risk of credential theft and unauthorized access.<\/li>\n<li>Educate end users on safe software acquisitionConduct awareness training focused on recognizing malvertising, deceptive download pages, and fraudulent installers \u2014 reinforcing that software should only be downloaded from official vendor websites or trusted app stores.<\/li>\n<\/ul>\n<p><strong>Post-incident recommended actions<\/strong><\/p>\n<ul>\n<li>Conduct comprehensive endpoint scans\u00a0using updated threat intelligence to detect known indicators of compromise<\/li>\n<li>Reimage compromised endpoints\u00a0and enforce immediate credential resets to eliminate persistence risks<\/li>\n<li>Verify and enforce Multi-Factor Authentication (MFA)\u00a0for all impacted users and systems not previously protected<\/li>\n<li>Strengthen behavioural monitoring and detection capabilities\u00a0to identify malicious activity and potential follow-on payloads<\/li>\n<li>Restrict installation of unverified or unauthorized software using application control and publisher validation policies<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Sophos X-Ops explores a malvertising campaign that leverages Google Ads to distribute an infostealer.<\/p>\n","protected":false},"author":6,"featured_media":71787,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[1481,7958,54,206,7957],"class_list":["post-73048","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-cybersecurity","tag-evilai","tag-security","tag-sophos","tag-tamperedchef"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/73048","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=73048"}],"version-history":[{"count":1,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/73048\/revisions"}],"predecessor-version":[{"id":73049,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/73048\/revisions\/73049"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/71787"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=73048"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=73048"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=73048"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}