BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

TamperedChef Malvertising Campaign Targets Users with Fake Software

TamperedChef: A Global Malvertising Campaign Delivering Stealthy JavaScript Backdoors Through Fake Software Installers

  • Threat actors use fake installers disguised as popular software in a global malvertising campaign called TamperedChef.
  • The campaign employs social engineering, SEO, and code-signing certificates from shell companies to evade detection and build user trust.
  • The Malware delivers a JavaScript backdoor to enable remote access, with infection concentrated mainly in the U.S. and affecting healthcare, construction, and manufacturing sectors.
  • TamperedChef is part of a wider set of attacks codenamed EvilAI, which leverages AI-related lures for malware distribution.
  • The malware family is also known as BaoLoader by some vendors but is primarily referred to as TamperedChef for consistency among Cybersecurity communities.

TamperedChef is a persistent global malvertising campaign where threat actors distribute malware through fake installers posing as commonly used software. This ongoing campaign, examined by Acronis Threat Research Unit (TRU), tricks users into downloading malicious files by exploiting popular search terms and deceptive ads. The main objective is to establish a foothold and deliver JavaScript malware that provides remote access and control.

- Advertisement -

The attackers use everyday application names and Search Engine Optimization (SEO) along with malicious advertising to lure victims. They also abuse digital code-signing certificates issued to shell companies from countries including the U.S., Panama, and Malaysia. These certificates enhance trust and help the malware evade security filters by making the fake applications seem legitimate. New certificates are frequently obtained under different company names once older ones are revoked, creating what Acronis describes as an “industrialized and business-like” infrastructure.

This malware family is part of a broader set of exploits called EvilAI, which targets users with AI-related software lures to spread threats. While some firms call this malware BaoLoader, Acronis uses the name TamperedChef to maintain uniformity in reporting due to its widespread adoption in cybersecurity.

In a typical attack, users seeking PDF editors or product manuals find malicious ads or poisoned URLs in search engines. Clicking these links leads to fake websites that prompt users to download a harmful installer. After installation, the malware launches a scheduled task via an XML file, which triggers an obfuscated JavaScript backdoor. This backdoor communicates with an external server, sending encrypted system information such as session and machine IDs in Base64-encoded JSON format via HTTPS.

The ultimate aims of these attacks remain unclear. Evidence suggests some variants facilitate advertising fraud, signaling financial motives. The threat actors may also monetize access by selling stolen data to other criminals in underground markets.

- Advertisement -

Infection rates are highest in the United States, with notable cases in Israel, Spain, Germany, India, and Ireland. The healthcare, construction, and manufacturing industries face the greatest impact, likely due to their frequent need for technical manuals and specialized equipment, which this campaign exploits.

Further details on this operation can be found in the full Acronis report.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

‘Godfather of Crypto’ Predicts Bitcoin Drop to $57K in 2026

Michael Terpin, an influential crypto investor, predicts the Bitcoin bull cycle peaked and will...

Kraken Urges US Tax Reforms After Filing 56M Forms

Kraken issued over 56 million tax forms to the IRS in 2025, with 18.5...

Harvester Deploys New Linux Backdoor in Espionage

The cyber-espionage group Harvester has deployed a new Linux variant of its GoGra backdoor...

Best Shiba Inu Buy Under $0.00001? Gains 6.5% Monthly

Shiba Inu (SHIB) has rallied 2.5% in the last 24 hours amid a wider...

Bitcoin Surging as Saylor Outpaces BlackRock; Musk Hint

Bitcoin surged nearly 30% from a low of $60,000 in early Q2 2026, approaching...

Must Read

What is Moon Tropica (CAH) – Technology, Tokenomics, Game Preview

Gaming enthusiasts and crypto enthusiasts, hHave you heard about Moon Tropica? If you're longing for that nostalgic feel of classic games from your childhood...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading