TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign

General News

Summary

Threat actors are using fake installers for popular software to spread TamperedChef malware through an ongoing global malvertising campaign. The attackers rely on poisoned search results, malicious ads, and signed binaries to make the downloads look legitimate. Once installed, the malware creates persistence and loads a JavaScript backdoor that connects to remote infrastructure for control and data collection. The campaign has affected multiple countries, with the highest concentration in the U.S., and it is hitting healthcare, construction, and manufacturing users in particular.

Classifications

industries
No industries detected
applications
Data Management

AskAI Classifications

Labels
Cybersecurity Software Backup and Disaster Recovery Software Endpoint Management Software

Linked Companies

Acronis
$100M to $250M
G DATA CyberDefense AG
$50M to $100M
Expel
$50M to $100M