A long-running and sophisticated malvertising, known as TamperedChef, continues to threaten organizations around the world, leveraging infected PDF documents to introduce malware into victims’ networks. The campaign has been detected for several years, but recent analysis by Sophos shows that the targeting has now become systematic and widespread, particularly in Europe, with Germany, the UK and France emerging as the main victims.

Targeting specific industries and specialized users
TamperedChef is not targeting randomly. Researchers have observed that it often focuses on organizations that rely on specialized technical equipment. Users in these organizations often refer to instruction manuals or technical PDFs to complete tasks or install software. The campaign exploits this very behavior, promoting infected documents that appear to provide the required files, while in reality they introduce infostealers and backdoor access to the network.
See also: RondoDox Botnet exploits vulnerability in HPE OneView
TamperedChef is designed to evade detection, with delays in the activation of the malware to ensure its presence on the system and its persistence on the network.
Multi-layered attack strategy
According to Sophos, the attack chain includes multiple advanced tactics:
- Activation delay and inactivity to avoid rapid detection.
- Deception software to hide its true function.
- Gradual delivery of the malicious payload to reduce suspicion.
- Abuse of code signing certificates.
- Techniques for avoiding endpoint protection mechanisms.
The campaign begins when a user searches for specific documents or software through a search engine. Attackers place malicious ads at the top of search results, either through SEO or paid promotion, with the goal of tricking users into clicking on them, believing they are downloading the desired file.

The malware behind the campaign
When the user downloads and opens the PDF, the infostealer, collecting data from the browser and establishing a connection to a command and control (C2) server. It then downloads an additional payload named ManualFinderApp.exe, which acts as both an infostealer and a backdoor, providing full access to the victim's network.
See also: Backdoor LOTUSLITE targets US political entities
To avoid detection, the malicious behavior is only activated 56 days after the file is downloaded. This makes it particularly difficult to identify the threat early and enhances the malware's ability to remain hidden for a long time.

Suggestions for users and organizations
Sophos recommends that users avoid clicking on links or pop-ups in advertisements and only download files from official and trusted websites.
For organizations, it is recommended:
- Implement policies to ensure that files and software only come from trusted sources.
- Use of multiple levels of endpoint security.
- Enable multi-factor authentication (MFA) to protect accounts even in the event of stolen credentials.
See also: StackWarp attack threatens confidential VMs on AMD
TamperedChef is an example of a modern, multi-layered threatthat combines social engineering, malware, and sophisticated evasion techniques, making it imperative for users and organizations to be informed to prevent attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
