Skip to content
Counterfeit installers facilitate global TamperedChef campaign

Counterfeit installers facilitate global TamperedChef campaign

Scworld November 20, 2025

Trojanized installers of widely known software have been leveraged to spread a JavaScript backdoor and achieve persistence as part of the ongoing global malvertising campaign TamperedChef , reports The Hacker News .

Attackers have poisoned Bing results for PDF editors and product manuals with links redirecting to NameCheap-registered domains that lure users into downloading the fake installers, according to an Acronis Threat Research Unit analysis. Agreeing to the licensing terms upon execution of the installer triggers a thank you message in a new browser tab, as an XML file creating a scheduled task for JavaScript malware delivery is covertly installed. Most compromised by the backdoor were healthcare, manufacturing, and construction organizations in the U.S, Israel, Spain, Germany, India, and Ireland.

"These industries appear especially vulnerable to this type of campaign, likely due to their reliance on highly specialized and technical equipment, which often prompts users to online for product manuals one of the behaviors exploited by the TamperedChef campaign," said Acronis researchers.

Extracted Entities

Attack Types (2)

Malware (1)

MITRE ATT&CK (1)