Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Google Ads Exploited to Deliver TamperedChef Through Malicious PDF Editor

The TamperedChef campaign has impacted over 100 organizations in 19 countries by distributing malicious PDF editing software via Google Ads. Sophos Managed Detection and Response (MDR) teams identified the operation in September 2025, revealing an attack…

The TamperedChef campaign has impacted over 100 organizations in 19 countries by distributing malicious PDF editing software via Google Ads. Sophos Managed Detection and Response (MDR) teams identified the operation in September 2025, revealing an attack infrastructure targeting browser credentials and establishing backdoor access on Windows systems.

The operation began in June 2025 with the registration of deceptive domains promoting a trojanized application, AppSuite PDF Editor. Malicious advertisements and search engine optimization tactics were used to lure users into downloading the infected installer. The malware remained dormant for 56 days, activating its credential-stealing capabilities on August 21, 2025.

Sophos MDR identified Germany as the most affected country, followed by the United Kingdom and France. The campaign targeted industries reliant on technical equipment, particularly those searching for appliance manuals and documentation. More than 300 systems were compromised before takedown operations commenced.

The TamperedChef operation utilized a 56-day dormancy period to evade detection, aligning with typical advertising campaign durations. Users clicking on sponsored search results were redirected to fraudulent domains hosting the Appsuite PDF.msi installer. Upon execution, the installer deployed PDFEditorSetup.exe and established persistence through registry modifications and scheduled tasks.

The TamperedChef campaign has impacted over 100 organizations in 19 countries by distributing malicious PDF editing software via Google Ads.
Madison Drake · Thehackingpost

The malware included an obfuscated JavaScript file (pdfeditor.js), believed to be AI-generated, which bypassed signature-based antivirus detection. The primary payload, PDF Editor.exe, functioned as both a legitimate tool and a hidden infostealer targeting browser-stored credentials. Security products and browser processes were enumerated and terminated to extract credentials using the Windows Data Protection API (DPAPI).

A secondary payload, ManualFinderApp.exe, established command-and-control communication with specific domains, enabling remote code execution and data exfiltration. Fraudulent code-signing certificates were used to bypass Windows SmartScreen protections. Although some certificates have been revoked, existing installations remain functional, and threat actors may acquire new credentials to continue operations.

Advertisement

Sophos deployed multiple protections against TamperedChef variants, including detection signatures for Mal/Isher-Gen, JS/Agent-BLMN, Troj/EvilAI-H, and OneStart.ai. Organizations are advised to reset passwords across enterprise accounts as browser-stored credentials are considered compromised. Security teams should monitor for suspicious scheduled tasks and registry modifications as indicators of TamperedChef activity.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories