Skip to content
ThreatCluster

TamperedChef Malware Campaign Targets Users via Signed Productivity Apps

First seen 21 May 2026, 20:49 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 22, 2026 at 20:40 UTC
  • TamperedChef malware uses signed productivity apps to deploy stealers and RATs.
  • Hundreds of campaigns have been linked to this evolving threat, affecting numerous users.
  • Detection of TamperedChef is challenging due to its disguise within legitimate software.

The TamperedChef malware campaign is exploiting trojanized productivity applications, including PDF editors and file converters, to deploy information stealers and remote access trojans (RATs). This large-scale threat has been linked to multiple activity clusters, with researchers tracking hundreds of campaigns. Users of these applications are at risk of credential theft and unauthorized remote access. The malware disguises itself within legitimate software, making detection challenging. Current threat intelligence suggests that this campaign is ongoing and evolving, with significant implications for user security. Organizations are urged to remain vigilant and monitor for unusual activity related to these applications.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 121d ago How this analysis works

Timeline

Recent
TamperedChef malware identified
Researchers reported a large-scale malware campaign using trojanized productivity apps to deploy malicious payloads.
Gbhackers
Recent
Multiple activity clusters linked
Security researchers identified activity clusters CL-CRI-1089, CL-UNK-1090, and CL-UNK-1110 associated with TamperedChef.
Gbhackers
Recent
Credential theft reported
The malware campaign is stealing user credentials and providing remote access to attackers.
Cybersecuritynews

More articles in this cluster (2)

Following this threat?

Track EvilAI in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed