TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign
Summary
Threat actors are using fake installers for popular software to spread TamperedChef malware through an ongoing global malvertising campaign. The attackers rely on poisoned search results, malicious ads, and signed binaries to make the downloads look legitimate. Once installed, the malware creates persistence and loads a JavaScript backdoor that connects to remote infrastructure for control and data collection. The campaign has affected multiple countries, with the highest concentration in the U.S., and it is hitting healthcare, construction, and manufacturing users in particular.
Classifications
industries
No industries detected
applications
Data Management
AskAI Classifications
Labels
Cybersecurity Software
Backup and Disaster Recovery Software
Endpoint Management Software