Threat Actors Leverage Google Ads to Weaponize PDF Editor with TamperedChef
## Cybersecurity: TamperedChef Malvertising Campaign
Cybersecurity: TamperedChef Malvertising Campaign
A malvertising campaign identified in September 2025 poses a significant threat to Windows users globally. Threat actors have created counterfeit PDF editing applications, promoting them through Google Ads to distribute the information-stealing malware, TamperedChef.
The malware specifically targets users searching for appliance manuals or PDF editing tools, exploiting common search behaviors to deliver infections across various industries and regions. The campaign officially commenced on Thu, Jun 26, 2025, with the registration of multiple look-alike websites promoting a trojanized application called AppSuite PDF Editor.
Users believed they were downloading legitimate software; however, the installer contained hidden malicious code designed to steal sensitive browser data. The malware remained dormant for approximately 56 days, aligning with typical advertising campaign cycles to maximize the number of infected devices before activating harmful behavior.
Sophos analysts and researchers identified the malware, discovering over 100 affected customer systems during managed detection and response operations. The investigation revealed that victims primarily came from Germany, the United Kingdom, and France, with at least 19 countries affected globally. The attackers targeted industries reliant on specialized equipment, where employees frequently search for product manuals online.
A malvertising campaign identified in September 2025 poses a significant threat to Windows users globally.
The Silent Infection: How TamperedChef Operates
TamperedChef employs sophisticated multi-stage deployment tactics designed to evade detection. Users click on malicious advertisements in search results, directing them to deceptive websites such as fullpdf.com and pdftraining.com. Here, they download the Appsuite-PDF.msi installer.
Upon execution, the installer drops a setup executable named PDFEditorSetup.exe, an obfuscated JavaScript file, and an additional executable. PDFEditorSetup.exe establishes persistence by creating registry entries and Windows scheduled tasks, ensuring the malware survives system restarts. The installer then deploys PDF Editor.exe, the infostealer component, which began harvesting browser credentials, cookies, and autofill data on Fri, Aug 21, 2025.
Attackers enhanced their operation by utilizing legitimate code-signing certificates from Malaysian and US-registered entities, allowing malicious files to bypass Windows SmartScreen protections and appear trustworthy. This layered infection process highlights how modern threat actors combine malvertising, legitimate-looking software interfaces, and system-level evasion techniques to increase infection success and minimize early detection.
Based on reporting by Cyber Security News.
