Malicious actors are exploiting fake installers that mimic popular software to trick users into installing malware as part of a global malvertising campaign dubbed TamperedChef.

The ultimate goal of the attacks is to establish persistence and deliver JavaScript malware that facilitates remote access and control, according to a report by the Acronis Threat Research Unit (TRU). The campaign is still ongoing, with new findings being discovered and the associated infrastructure remaining active.
Operators rely on social engineering using everyday app names, malicious advertising, search engine optimization (SEO), and abusive digital certificates aimed at increasing user trust and avoiding security detection , researchers Darrel Virtusio and Jozsef Gegeny said .
See also: Nova Stealer: Steals crypto wallet data from macOS users
TamperedChef Campaign: Malware Distribution
TamperedChef is the name given to a long-running campaign that has exploited seemingly legitimate installers for various utilities to distribute information-stealing malware (of the same name). It is believed to be part of a broader set of attacks codenamed EvilAI, which uses decoys related to artificial intelligence (AI) tools and software to spread malware.
Acronis described the infrastructure as “industrial and enterprise-grade,” essentially allowing operators to continuously generate new certificates and exploit the inherent trust associated with signed applications (to disguise malware as legitimate).

The malware tracked as TamperedChef by Truesec and G DATA is also reported as BaoLoader by Expel. It is different from the original TamperedChef malware that was embedded in a malicious recipe app distributed as part of the EvilAI campaign.
See also: New .NET malware hides Lokibot inside PNG/BMP files
Acronis told The Hacker News that it uses TamperedChef to refer to the malware family, as it has already been widely adopted by the cybersecurity community. This helps avoid confusion and maintain consistency with existing publications and detection names used by other vendors.
How does the attack work?
Once the malicious installer is executed, users are prompted to agree to the program's license terms. It then opens a new browser tab to display a thank you message once the installation is complete. However, in the background, an XML file is installed to create a scheduled task, designed to launch an obfuscated JavaScript backdoor.
The backdoor connects to an external server and sends basic information, such as session ID, machine ID, and other metadata in the form of a JSON string that is encrypted and encoded in Base64 over HTTPS.

The ultimate goals of the campaign remain unclear. Some versions have been found to facilitate ad fraud, suggesting financial motives. It is also possible that the malicious actors seek to exploit their access by selling it to other cybercriminals or to harvest sensitive data and sell it on underground forums.
See also: Sneaky 2FA Phishing Kit Adds BitB Pop-ups
Telemetry data shows that a significant concentration of infections has been identified in the U.S. and to a lesser extent in Israel, Spain, Germany, India and Ireland. The sectors healthcare, construction and industrial are the most affected.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
These sectors appear to be particularly vulnerable to this type of campaign, likely due to their reliance on specialized and technical equipment, which often leads users to search for online product manuals – one of the behaviors exploited by the TamperedChef campaign.
