TamperedChef Malware Campaign Targets Users via Signed Productivity Apps
Article Content
- •TamperedChef malware uses signed productivity apps to deploy stealers and RATs.
- •Hundreds of campaigns have been linked to this evolving threat, affecting numerous users.
- •Detection of TamperedChef is challenging due to its disguise within legitimate software.
The TamperedChef malware campaign is exploiting trojanized productivity applications, including PDF editors and file converters, to deploy information stealers and remote access trojans (RATs). This large-scale threat has been linked to multiple activity clusters, with researchers tracking hundreds of campaigns. Users of these applications are at risk of credential theft and unauthorized remote access. The malware disguises itself within legitimate software, making detection challenging. Current threat intelligence suggests that this campaign is ongoing and evolving, with significant implications for user security. Organizations are urged to remain vigilant and monitor for unusual activity related to these applications.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track EvilAI in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…