TamperedChef Malvertising Campaign Targets Users with Fake Software

TamperedChef: A Global Malvertising Campaign Delivering Stealthy JavaScript Backdoors Through Fake Software Installers

  • Threat actors use fake installers disguised as popular software in a global malvertising campaign called TamperedChef.
  • The campaign employs social engineering, SEO, and code-signing certificates from shell companies to evade detection and build user trust.
  • The Malware delivers a JavaScript backdoor to enable remote access, with infection concentrated mainly in the U.S. and affecting healthcare, construction, and manufacturing sectors.
  • TamperedChef is part of a wider set of attacks codenamed EvilAI, which leverages AI-related lures for malware distribution.
  • The malware family is also known as BaoLoader by some vendors but is primarily referred to as TamperedChef for consistency among Cybersecurity communities.

TamperedChef is a persistent global malvertising campaign where threat actors distribute malware through fake installers posing as commonly used software. This ongoing campaign, examined by Acronis Threat Research Unit (TRU), tricks users into downloading malicious files by exploiting popular search terms and deceptive ads. The main objective is to establish a foothold and deliver JavaScript malware that provides remote access and control.

- Advertisement -

The attackers use everyday application names and Search Engine Optimization (SEO) along with malicious advertising to lure victims. They also abuse digital code-signing certificates issued to shell companies from countries including the U.S., Panama, and Malaysia. These certificates enhance trust and help the malware evade security filters by making the fake applications seem legitimate. New certificates are frequently obtained under different company names once older ones are revoked, creating what Acronis describes as an “industrialized and business-like” infrastructure.

This malware family is part of a broader set of exploits called EvilAI, which targets users with AI-related software lures to spread threats. While some firms call this malware BaoLoader, Acronis uses the name TamperedChef to maintain uniformity in reporting due to its widespread adoption in cybersecurity.

In a typical attack, users seeking PDF editors or product manuals find malicious ads or poisoned URLs in search engines. Clicking these links leads to fake websites that prompt users to download a harmful installer. After installation, the malware launches a scheduled task via an XML file, which triggers an obfuscated JavaScript backdoor. This backdoor communicates with an external server, sending encrypted system information such as session and machine IDs in Base64-encoded JSON format via HTTPS.

The ultimate aims of these attacks remain unclear. Evidence suggests some variants facilitate advertising fraud, signaling financial motives. The threat actors may also monetize access by selling stolen data to other criminals in underground markets.

- Advertisement -

Infection rates are highest in the United States, with notable cases in Israel, Spain, Germany, India, and Ireland. The healthcare, construction, and manufacturing industries face the greatest impact, likely due to their frequent need for technical manuals and specialized equipment, which this campaign exploits.

Further details on this operation can be found in the full Acronis report.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Soldier used military secrets for $150K crypto bets.

An Israeli reserve soldier and a civilian accomplice face charges for allegedly using military...

BitGo, 21Shares Expand ETF Staking & Custody Partnership

BitGo and 21Shares have expanded their partnership to provide custody, trading, and staking services...

North Korean Hackers Use Google’s Gemini AI for Cyber Recon

Google's threat intelligence team observed the North Korean hacking group UNC2970 using the generative...

Binance SAFU Fund Now Holds $1 Billion in Bitcoin

Binance has purchased $305 million in Bitcoin for its user protection fund, bringing its...

Jeffy Yu, Crypto Founder Who Faked Death, Allegedly Dies

Crypto founder Jeffy Yu is alleged to have committed suicide in Roseville on New...

Must Read

12 Hosting Providers To Buy VPS With Bitcoin: An Expert Guide for 2026

You need a VPS. You want to pay with Bitcoin. Simple enough, right?Not quite. The market for crypto VPS = VPS hosting that accepts...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!