Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Gunra Ransomware Exploits Fortinet VPN Flaws, Bypasses MFA
August 10, 2026
Anthropic Claude: New Security Feature Automates Agent Access Approvals
August 10, 2026
Critical Vulnerability Lets Attackers Bypass MFA in Windows 11 and Entra ID
August 10, 2026
Home/Threats/TamperedChef Malware Abuses Signed Apps to Deliver Stealers and RATs
Threats

TamperedChef Malware Abuses Signed Apps to Deliver Stealers and RATs

Key Takeaways A new malware campaign, dubbed TamperedChef (also known as EvilAI), is actively distributing information stealers and Remote Access Trojans (RATs) by embedding them within seemingly...

Marcus Rodriguez
Marcus Rodriguez
May 21, 2026 6 Min Read
56 0

Key Takeaways

  • A new malware campaign, dubbed TamperedChef (also known as EvilAI), is actively distributing information stealers and Remote Access Trojans (RATs) by embedding them within seemingly legitimate, signed productivity applications.
  • The threat actors behind TamperedChef have leveraged sophisticated tactics, including the establishment of shell companies to acquire legitimate code-signing certificates, making their malicious applications appear trustworthy to victims and standard security tools.
  • Since early 2023, hundreds of these campaigns have been observed globally, with researchers identifying over 4,000 unique samples and more than 100 variants, affecting over 50% of monitored enterprise environments.
  • Infections can remain dormant for weeks or months before deploying their full payload, which includes exfiltrating credentials, establishing remote control, and in some cases, turning victim machines into proxy nodes.

Sophisticated TamperedChef Malware Evades Detection with Signed Productivity Apps

A widespread and persistent malware operation, identified as TamperedChef, or alternatively EvilAI, has been observed leveraging a highly deceptive strategy: packaging potent information stealers and Remote Access Trojans (RATs) within digitally signed productivity applications. This sophisticated campaign aims to surreptitiously compromise systems, enabling attackers to harvest sensitive user credentials and maintain persistent control over infected machines. For a comprehensive breakdown of this threat, readers can refer to the Unit42 report.

Table Of Content

  • Key Takeaways
  • Sophisticated TamperedChef Malware Evades Detection with Signed Productivity Apps
  • Extensive Global Impact and Organized Operations
  • Abuse of Code-Signing Certificates for Trust Evasion
  • Payloads: Stealers, RATs, and Post-Infection Behavior
  • What You Should Do
  • Indicators of Compromise (IoCs)

Since the beginning of 2023, threat actors have deployed malware hidden within common utility applications, such as PDF editors, calendar tools, ZIP extractors, and GIF creators. Crucially, these applications function exactly as advertised, which significantly lowers victim suspicion and allows the malicious components to go undetected. The malware can lie dormant on a device for extended periods, sometimes weeks or even months, before initiating its payload, thereby bypassing many conventional security measures.

Extensive Global Impact and Organized Operations

Analysts at Unit42 have meticulously tracked three distinct clusters of this activity, designated CL-CRI-1089, CL-UNK-1090, and CL-UNK-1110. According to their findings, shared with Cyber Security News (CSN), researchers discovered more than 4,000 unique samples and over 100 different variants associated with these campaigns. The global reach of TamperedChef is significant, with infections detected in over half of the enterprise environments monitored worldwide.

A key factor contributing to TamperedChef’s danger is its meticulous imitation of legitimate software. The distribution infrastructure includes professionally designed download pages featuring legal disclaimers, contact information, and straightforward download buttons, all hosted on domains that appear entirely authentic. The sheer scale of this operation indicates a well-resourced and highly organized threat group. Researchers estimate that the operators of just one cluster invested upwards of $10,000 in acquiring code-signing certificates alone. This substantial financial commitment suggests a long-term, profit-motivated campaign, far exceeding the typical scope of less sophisticated adware operations.

Abuse of Code-Signing Certificates for Trust Evasion

One of the most insidious tactics employed by TamperedChef is the use of legitimate code-signing certificates to imbue their malicious payloads with an aura of trustworthiness. These certificates, typically issued to verified companies, lead most security solutions to treat the signed software as benign. To exploit this, the threat actors established a network of shell companies across various countries, including Ukraine, Malaysia, Israel, the UK, and the US, to obtain valid certificates.

The CL-CRI-1089 cluster, for instance, was linked to 34 unique code-signing entities, identified through shared certificate usage, overlapping code, and corporate structure analysis. In one example, the Calendaromatic campaign distributed a self-extracting archive containing a fully functional calendar application alongside a covert remote access Trojan. Once activated, this RAT communicated with a command-and-control server to fetch a second-stage payload, further compromising the victim’s system.

The CL-UNK-1090 cluster demonstrated an even more integrated approach, with the same group reportedly owning both the advertising agencies and the companies responsible for signing the malware. Over 20,000 unique advertisements related to this cluster were tracked via ad transparency platforms, promoting campaigns such as CrystalPDF, OneZip, and Easy2Convert. The operators also leveraged generative AI to rapidly create numerous distribution websites, each appearing similar but possessing distinct underlying code.

Payloads: Stealers, RATs, and Post-Infection Behavior

Upon activation, a TamperedChef application delivers one of two primary payload categories, depending on the specific campaign. The first category includes adware and browser hijackers, designed to redirect search queries and seize control of browsing activities.

The second, and more severe, category involves the deployment of information stealers and remote access Trojans. These tools are engineered to target saved credentials and grant attackers the ability to execute commands remotely on the compromised system. Second-stage payloads are frequently delivered weeks after the initial installation, via an upstream API connection, long after any initial suspicion has subsided.

In certain campaigns, such as AppSuite, researchers also identified proxy-style malware that reroutes traffic through infected machines. The CL-CRI-1089 cluster exhibited the most aggressive credential theft capabilities, while the CL-UNK-1090 cluster favored more stealthy, in-memory payloads, leaving fewer forensic traces on disk.

What You Should Do

  • Enhance Endpoint Security: Ensure all endpoint detection and response (EDR) solutions are fully updated across all devices to detect and block TamperedChef variants.
  • Implement Enterprise Browsers: Utilize enterprise-grade browsers that incorporate robust malicious download blocking features before files reach end-users.
  • Strengthen User Awareness Training: Educate employees on the risks associated with downloading unfamiliar software, emphasizing that even professionally designed download sites can host malicious content.
  • Prompt Incident Response: In the event of a suspected infection, immediately quarantine affected files, eliminate any persistence mechanisms (e.g., scheduled tasks), reset credentials for all potentially compromised accounts, and thoroughly review access logs for signs of credential misuse.
  • Monitor for IoCs: Integrate the provided Indicators of Compromise (IoCs) into your security information and event management (SIEM) systems and threat intelligence platforms for proactive detection.

Indicators of Compromise (IoCs)

Type Indicator Description
SHA256 Hash 248de1470771904462c91f146074e49b3d7416844ec143ade53f4ac0487fdb4 RapiDoc binary containing PDB path, linked to CANDY TECH LTD (CL-UNK-1090)
SHA256 Hash 42231bfa7c7bd4a8ff12568074f83de8e4ec95c226230cccc6616a1a4416de268 RapiDoc binary containing PDB path, linked to CANDY TECH LTD (CL-UNK-1090)
PDB Path D:!WorkClients<user>ProjectsRapiDocSrcForTestsRapiDocx64ReleaseRapiDocRapiDoc.pdb Program database path found in RapiDoc binaries, likely left by mistake during build
Domain onezipapp[.]com Distribution site for OneZip malware, signed by TAU CENTAURI LTD (CL-UNK-1090)
Domain crystalpdf[.]com Distribution site for CrystalPDF, used by CL-UNK-1090 cluster
Domain Pattern pixel.toolname[.]com C2 domain pattern used by PixelCheck variant (PDFPrime/ManualzPDF campaigns, CL-CRI-1089)
Code Signer CROWN SKY LLC Code-signing entity used in Calendaromatic campaign (CL-CRI-1089)
Code Signer MARKET FUSION INNOVATIONS LLC Code-signing entity linked to Calendaromatic campaign (CL-CRI-1089)
Code Signer CANDY TECH LTD Core signing and advertising entity for CL-UNK-1090 cluster
Code Signer TAU CENTAURI LTD Signing entity linked to OneZip campaign (CL-UNK-1090)
Code Signer B.L.A ASPIRE LTD Signing entity for JustConvertFiles binaries (CL-UNK-1090)
Code Signer PASTEL CONCEPTION LTD Signing entity for JustConvertFiles; linked to PDFPilot, SwiftNav, ShinyPDF, FileEase
Code Signer BUZZ BOOST ADVERTISERS LLC Certificate entity linked to PixelCheck variant (CL-CRI-1089)
Code Signer ADSMARKETO LLC Certificate entity linked to PixelCheck variant (CL-CRI-1089)
Code Signer ADVANTAGE WEB MARKETING LLC Certificate entity linked to PixelCheck variant (CL-CRI-1089)
Code Signer Europae-Solutio Ltd Certificate entity linked to PixelCheck variant (CL-CRI-1089)
Code Signer SP Development and Solution Limited Certificate entity linked to PixelCheck variant (CL-CRI-1089)
Code Signer LLC MATCH-TWO-USERS Certificate entity linked to PixelCheck variant (CL-CRI-1089)
Code Signer Monetize forward LLC Certificate entity linked to PixelCheck variant (CL-CRI-1089)
Malware Sample calendaromatic-win_x64.exe First-stage binary from Calendaromatic campaign (CL-CRI-1089)
Malware Sample resources.neu Obfuscated NeutralinoJS resource file containing C2 logic, Calendaromatic campaign
File Name RapiDoc.pdb Debug symbol file found in RapiDoc binaries (CL-UNK-1090)
Campaign Name AppSuite PDF Malicious PDF editor spreading TamperedChef malware; observed deploying proxy-style payloads
Campaign Name Calendaromatic Calendar app trojan; earliest tracked CL-CRI-1089 activity (late 2023)
Campaign Name CrystalPDF Malicious PDF tool distributed by CL-UNK-1090; hosted at crystalpdf[.]com
Campaign Name JustAskJacky App distributed by CL-UNK-1110 cluster
Campaign Name OneZip Malicious ZIP tool signed by TAU CENTAURI LTD; distributed via onezipapp[.]com
Campaign Name PDFPrime / ManualzPDF Early CL-CRI-1089 campaigns sharing code and C2 patterns (PixelCheck variant)
Campaign Name ZipMakerPro TamperedChef-style app linked to CANDY TECH LTD (CL-UNK-1090)
Campaign Name GifsMakerPro TamperedChef-style app linked to CANDY TECH LTD (CL-UNK-1090)
Campaign Name ScreensRecorder TamperedChef-style app linked to CANDY TECH LTD (CL-UNK-1090)
Campaign Name RapiDoc App with CANDY TECH LTD copyright; contained leaked PDB path (CL-UNK-1090)
Campaign Name JustConvertFiles Malicious file conversion tool distributed by CANDY TECH LTD (CL-UNK-1090)
Campaign Name PDFPilot Campaign linked to B.L.A ASPIRE LTD and PASTEL CONCEPTION LTD (CL-UNK-1090)
Campaign Name SwiftNav Campaign linked to B.L.A ASPIRE LTD and PASTEL CONCEPTION LTD (CL-UNK-1090)
Campaign Name ShinyPDF Campaign linked to B.L.A ASPIRE LTD and PASTEL CONCEPTION LTD (CL-UNK-1090)
Campaign Name FileEase Campaign linked to B.L.A ASPIRE LTD and PASTEL CONCEPTION LTD (CL-UNK-109)

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwareSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Fake Microsoft Teams downloads deploy ValleyRAT malware

Next Post

Megalodon Malware Hijacks 5,500+ GitHub Repositories in 6 Hours

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks
August 10, 2026
Critical Red Hat ACM Vulnerability Lets Attackers Gain Cluster-Admin Access
August 10, 2026
GitHub Expands Malware Detection to 8 Package Registries
August 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us