HomeSecurityTamperedChef malware mimics productivity tools

TamperedChef malware imitates productivity tools

A sophisticated malware campaign has emerged that uses seemingly legitimate productivity tools to infiltrate systems and steal sensitive information. The TamperedChef malware represents a worrying evolution in threat actors' tactics, leveraging trojanized applications disguised as calendar tools and image viewers to bypass traditional security defenses.

TamperedChef malware

This campaign demonstrates how cybercriminals are increasingly exploiting users' trust in digitally signed software to facilitate initial access and establish permanent access points in targeted environments.

The campaign focuses on two main applications: Calendaromatic.exe and ImageLooker.exe, which are disguised as innocent productivity software while hosting malicious capabilities. These applications are distributed via self-extracting 7-Zip archives that exploit CVE-2025-0411 to bypass Windows Mark of the Web protections. As a result, the applications run without triggering SmartScreen warnings or other security checks.

See also: Hackers use Facebook and Google ads to steal data

The campaign leverages deceptive advertising and search engine optimization techniques to direct victims to malicious downloads, often targeting users looking for free productivity utilities.

Field Effect analysts discovered the campaign on September 22, 2025, during an analysis of a potentially unwanted application flagged by Microsoft Defender . Their investigation revealed a broader distribution network that includes multiple suspicious signature publishers and command-and-control infrastructure.

Researchers discovered that both malicious applications were digitally signed by entities such as CROWN SKY LLC and LIMITED LIABILITY COMPANY APPSOLUTE, providing a veil of legitimacy that helps bypass user suspicion and endpoint defenses.

TamperedChef malware imitates productivity tools

TamperedChef malware: Infection impacts

The impact of malware extends beyond simple data theft, as it allows for complete system compromise through browser hijacking, credential harvesting, and persistent backdoor access.

TamperedChef demonstrates particular sophistication in its ability to extract credentials and session informationstored in the browser, while simultaneously redirecting web traffic and modifying browser settings to facilitate ongoing malicious activities.

See also: XWorm campaign shifts to fileless malware

It also exploits modern application frameworks and advanced coding techniques. Both Calendaromatic.exe and ImageLooker.exe are built using NeutralinoJS, a lightweight desktop framework that allows arbitrary JavaScript code to be executed within native applications. This choice of framework allows the malware to interact seamlessly with system APIs while maintaining the appearance of legitimate desktop software.

The malware uses Unicode homoglyphs as a primary evasion mechanism, encoding malicious payloads within seemingly innocent API responses. This technique allows the malware to bypass traditional string-based detection systems and signature matching algorithms that security products rely on for identification.

When executed, the TamperedChef malware decodes these hidden payloads and runs them via the NeutralinoJS runtime, effectively creating a covert execution channel that operates beneath the radar of conventional monitoring systems.

Persistence mechanisms include the creation of scheduled tasks and registry modifications using specific command-line flags such as –install, –enableupdate, and –fullupdate. After successful installation, the malware establishes direct communication with command and control servers, including calendaromatic[.]com and movementxview[.]com, allowing remote operators to issue commands and extract collected data. Network communication is carried out over encrypted channels, further complicating detection and analysis efforts.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

TamperedChef malware imitates productivity tools

Malware protection

The first and most important way to protect yourself from malware is to install reliable security software. This software should include protection against viruses, spyware, malware, and other attacks.

Additionally, it's important to keep your operating system and all your applications up to date. These updates often include security that can protect  computer from the latest known malware.

See also: PureMiner malware: Hackers exploit SVG files for distribution

You should also be careful with the emails and messages you receive. A lot of malware is spread through phishing attacks, so avoid opening attachments or clicking on links from unknown sources.

Using strong passwords and changing them regularly can also help protect against attacks. Also, using two-factor authentication can add an extra layer of security.

Finally, information security training can be particularly useful. Understanding the ways in which malware invades system and how to protect against it can help you stay safe.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS