HomeSecurityTamperedChef: Malvertising campaign distributes malware via PDF manuals

TamperedChef: Malvertising campaign distributes malware via PDF manuals

A long-running and sophisticated malvertising, known as TamperedChef, continues to threaten organizations around the world, leveraging infected PDF documents to introduce malware into victims’ networks. The campaign has been detected for several years, but recent analysis by Sophos shows that the targeting has now become systematic and widespread, particularly in Europe, with Germany, the UK and France emerging as the main victims.

TamperedChef Malvertising

Targeting specific industries and specialized users

TamperedChef is not targeting randomly. Researchers have observed that it often focuses on organizations that rely on specialized technical equipment. Users in these organizations often refer to instruction manuals or technical PDFs to complete tasks or install software. The campaign exploits this very behavior, promoting infected documents that appear to provide the required files, while in reality they introduce infostealers and backdoor access to the network.

See also: RondoDox Botnet exploits vulnerability in HPE OneView

TamperedChef is designed to evade detection, with delays in the activation of the malware to ensure its presence on the system and its persistence on the network.

Multi-layered attack strategy

According to Sophos, the attack chain includes multiple advanced tactics:

  • Activation delay and inactivity to avoid rapid detection.
  • Deception software to hide its true function.
  • Gradual delivery of the malicious payload to reduce suspicion.
  • Abuse of code signing certificates.
  • Techniques for avoiding endpoint protection mechanisms.

The campaign begins when a user searches for specific documents or software through a search engine. Attackers place malicious ads at the top of search results, either through SEO or paid promotion, with the goal of tricking users into clicking on them, believing they are downloading the desired file.

TamperedChef: Malvertising campaign distributes malware via PDF manuals

The malware behind the campaign

When the user downloads and opens the PDF, the infostealer, collecting data from the browser and establishing a connection to a command and control (C2) server. It then downloads an additional payload named ManualFinderApp.exe, which acts as both an infostealer and a backdoor, providing full access to the victim's network.

See also: Backdoor LOTUSLITE targets US political entities

To avoid detection, the malicious behavior is only activated 56 days after the file is downloaded. This makes it particularly difficult to identify the threat early and enhances the malware's ability to remain hidden for a long time.

TamperedChef: Malvertising campaign distributes malware via PDF manuals

Suggestions for users and organizations

Sophos recommends that users avoid clicking on links or pop-ups in advertisements and only download files from official and trusted websites.

For organizations, it is recommended:

  • Implement policies to ensure that files and software only come from trusted sources.
  • Use of multiple levels of endpoint security.
  • Enable multi-factor authentication (MFA) to protect accounts even in the event of stolen credentials.

See also: StackWarp attack threatens confidential VMs on AMD

TamperedChef is an example of a modern, multi-layered threatthat combines social engineering, malware, and sophisticated evasion techniques, making it imperative for users and organizations to be informed to prevent attacks.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS