Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Interview: Shopify CISO Andrew Dunbar on Securing an E-Commerce Giant

June 26, 2026

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»TamperedChef Malvertising Campaign Drops Malware via Fake PDF Manuals
News

TamperedChef Malvertising Campaign Drops Malware via Fake PDF Manuals

Team-CWDBy Team-CWDJanuary 16, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A long-running malvertising campaign is dropping backdoor malware onto the networks of organizations around the world through trojanized PDF documents.

Dubbed TamperedChef, the malvertising campaign has previously been identified, but researchers at Sophos have detailed how targeting has become widespread across Europe: organizations in Germany, the UK and France being the most common victims.

The campaign has infected organizations across a range of industries, but researchers noted how it has often hit organizations which rely heavily on specialized technical equipment, ones in which users are likely to commonly refer to – and search for – instruction manuals.

It is this behaviour which TamperedChef is exploiting to infect organizations with infostealers, with a focus on credential theft and backdoor access to networks.

The campaign has been designed to avoid detection, with delays to the malware being deployed to ensure persistence on networks.

This large, multi-layered distribution network featured multiple advanced tactics, including a delayed activation/dormancy period, decoy software, staged payload delivery, staged payload delivery, abuse of code-signing certificates, and efforts to evade endpoint protection mechanisms,” said Sophos.

TamperedChef Attack Chain in Detail

The attack chain starts when someone uses a search engine to look for something, particularly a query relating to appliance manuals or PDF editing software.

As part of the campaign, the attackers have created malicious adverts which appear at the top of related search results, either via SEO, paid promotion or both. The aim is simple: if the advert is at the top of the page and looks like it contains what the user is looking for, they’ll click on it.

These adverts direct the use to malicious sites which prompt the users to download files – under the pretence of the document that they’re searching for is what they’re downloading. It’s this which leads to being infected with the infostealer.

“Upon execution, the infostealer harvests browser-stored data, establishes a connection to a command-and-control (C2) server for data exfiltration, and retrieves an additional payload and retrieves an additional payload named ManualFinderApp.exe. This file is a trojanized application that functions as an infostealer and a backdoor,” said Sophos.

However, to avoid detection – and user suspicion – the malicious behaviour doesn’t begin until 56 days after the download.

“The threat actors behind the TamperedChef campaign crafted convincing malicious applications, leveraged targeted advertising to achieve large-scale distribution,” said Sophos.

To help avoid falling victim to malvertising campaigns like TamperedChef, Sophos recommended that users avoid clicking installation links or pop-ups in online adverts but instead rely on official sites to download the required documents.

For organizations, it is recommended that information security teams apply appropriate controls to ensure that files and software can only be downloaded from approved and trusted sources.

Multi-factor authentication should also be applied to accounts to help protect them from being actively compromised, even in the event of passwords being stolen.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAI Automation Exploits, Telecom Espionage, Prompt Poaching & More
Next Article Why LinkedIn is a hunting ground for threat actors – and how to protect yourself
Team-CWD
  • Website

Related Posts

News

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026
News

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026
News

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What are brushing scams and how do I stay safe?

December 24, 2025

Top IRS scams to look out for in 2026

February 10, 2026

A stealthy RAT burrowing deep into Android devices

May 26, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.