














A Heimdal investigation has revealed that the TamperedChef malware, disguised as free productivity software, has infected endpoints across multiple European organizations. The campaign used advanced obfuscation techniques to evade traditional detection.
Heimdal Security’s Managed Extended Detection and Response (MXDR) team found TamperedChef infections in 0.03% of its European customer base. The number may sound small, but across the whole region it points to a much larger problem.
The campaign, first observed in late June 2025, spread through a fake PDF editing tool and remained dormant until August 21, when it activated across compromised endpoints.
“It’s simple,” explains Marian, Heimdal’s threat intel security analyst.
“A user needs a specific tool not available in their standard software suite, like Adobe Pro which requires an expensive license, so they search online for free alternatives.”
This behavior allowed attackers to blend malicious activity with legitimate productivity software use, exploiting everyday user habits.
The malware masquerades as AppSuite PDF Editor, a convincing PDF editing tool promoted via Google advertising campaigns and compromised websites.
Heimdal confirmed infections across multiple European organizations, with the fake editor functioning normally for nearly two months before switching into malicious mode.
Research by Truesec supports Heimdal’s findings, showing that the malware’s activation after a 56-day dormancy period mirrors Google’s advertising cycles.
Researchers suggest this timing was deliberate to maximize exposure while minimizing detection risks.
Heimdal telemetry shows the malware’s core component, pdfeditor.js, is heavily obfuscated and was flagged by its NGAV behavioral engine (!msr).
According to Truesec and G DATA, the obfuscation may be AI or LLM generated, producing unique code variants that evade signature-based antivirus solutions.
The malware operates with a multi-component architecture that includes:
Commands such as –install, –fullupdate, and –check allow attackers to create tasks, activate payloads, and contact C2 servers.
Heimdal’s investigation revealed infections traced back to domains including inst.productivity-tools.ai and vault.appsuites.ai.
Broader infrastructure analysis from Truesec identified more than 40 distribution domains, with professional-sounding names such as:
The malware was also digitally signed. According to Truesec, the signatures came from four suspicious companies in Malaysia:
All of these appear to operate AI-generated websites.
On the command-and-control side, Heimdal has tracked activity (and blocked with our DNS software) linked to mka3e8.com.
Expel research also points to 5b7crp.com and y2iax5.com as part of the same infrastructure. Other servers have been reported in community feeds but remain unconfirmed.
The TamperedChef operation is not isolated. Expel has linked it to earlier unwanted software campaigns including ManualFinder.
Truesec notes overlaps with OneStart Browser and Epibrowser, which used similar infrastructure and digital certificates.
Together, the evidence points to a professional operation with continuity stretching back to at least August 2024.
Traditional antivirus solutions failed to flag the malware during its dormancy period.
Heimdal’s behavioral detection, however, spotted suspicious activity and quickly prompted the creation of a custom Sysmon detection rule to search for IoCs.
This rule uncovered additional infections, including dormant installations that had not yet activated.
Once active, the malware exfiltrates sensitive data including:
Persistence is maintained through registry keys and scheduled tasks, making removal unreliable without full reimaging.
Heimdal recommends complete reimaging combined with credential resets for all affected users.
Security teams can use the following indicators to detect infections related to TamperedChef:
The campaign illustrates two converging trends:
As Marian notes: “The golden rule in cybersecurity is that if something is free, then you are the product, or at least you will become one.”
Heimdal advises organizations to:
Adelina Deaconu, head of MXDR at Heimdal, said: “Manual removal of the malware’s artifacts is not considered a safe remediation step. Reimaging should be mandatory.”
For incident responders who need to confirm infections before reimaging, the following artifacts are typically present:
C:\Users\[username]\AppData\Local\Programs\PDFEditor\C:\Users\[username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PDF Editor.lnkC:\Users\[username]\Desktop\PDF Editor.lnkappsuite-pdf*.msiHKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\PDFEditorUpdaterPDFEditorScheduledTaskIf you liked this article, follow us on LinkedIn, X, Facebook, and Youtube, for more cybersecurity news and topics.
Head of Content at Heimdal. A journalist by trade who cares about helping MSPs and security teams make better decisions, enjoy their work, and see real results.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。