Google Ads Exploited to Deliver TamperedChef Through Malicious PDF Editor
The TamperedChef campaign has impacted over 100 organizations in 19 countries by distributing malicious PDF editing software via Google Ads. Sophos Managed Detection and Response (MDR) teams identified the operation in September 2025, revealing an attack…
The TamperedChef campaign has impacted over 100 organizations in 19 countries by distributing malicious PDF editing software via Google Ads. Sophos Managed Detection and Response (MDR) teams identified the operation in September 2025, revealing an attack infrastructure targeting browser credentials and establishing backdoor access on Windows systems.
The operation began in June 2025 with the registration of deceptive domains promoting a trojanized application, AppSuite PDF Editor. Malicious advertisements and search engine optimization tactics were used to lure users into downloading the infected installer. The malware remained dormant for 56 days, activating its credential-stealing capabilities on August 21, 2025.
Sophos MDR identified Germany as the most affected country, followed by the United Kingdom and France. The campaign targeted industries reliant on technical equipment, particularly those searching for appliance manuals and documentation. More than 300 systems were compromised before takedown operations commenced.
The TamperedChef operation utilized a 56-day dormancy period to evade detection, aligning with typical advertising campaign durations. Users clicking on sponsored search results were redirected to fraudulent domains hosting the Appsuite PDF.msi installer. Upon execution, the installer deployed PDFEditorSetup.exe and established persistence through registry modifications and scheduled tasks.
The TamperedChef campaign has impacted over 100 organizations in 19 countries by distributing malicious PDF editing software via Google Ads.
The malware included an obfuscated JavaScript file (pdfeditor.js), believed to be AI-generated, which bypassed signature-based antivirus detection. The primary payload, PDF Editor.exe, functioned as both a legitimate tool and a hidden infostealer targeting browser-stored credentials. Security products and browser processes were enumerated and terminated to extract credentials using the Windows Data Protection API (DPAPI).
A secondary payload, ManualFinderApp.exe, established command-and-control communication with specific domains, enabling remote code execution and data exfiltration. Fraudulent code-signing certificates were used to bypass Windows SmartScreen protections. Although some certificates have been revoked, existing installations remain functional, and threat actors may acquire new credentials to continue operations.
Sophos deployed multiple protections against TamperedChef variants, including detection signatures for Mal/Isher-Gen, JS/Agent-BLMN, Troj/EvilAI-H, and OneStart.ai. Organizations are advised to reset passwords across enterprise accounts as browser-stored credentials are considered compromised. Security teams should monitor for suspicious scheduled tasks and registry modifications as indicators of TamperedChef activity.
Based on reporting by GBHackers.
