TamperedChef Malware Disguised as Fake PDF Editors Steals Credentials and Cookies

In order to distribute a new information stealer known as TamperedChef, cybersecurity experts have uncovered a cybercrime campaign that uses malvertising techniques to send victims to phony websites.

In a study released on Wednesday, Truesec researchers Mattias Wåhlén, Nicklas Keijser, and Oscar Lejerbäck Wolf stated that the goal is to trick victims into downloading and installing a trojanized PDF editor that contains an information-stealing Trojan known as TamperedChef. Credentials and site cookies are among the sensitive data that the malware is intended to collect.

The campaign’s main tactic is the use of multiple fraudulent websites to advertise an installer for AppSuite PDF Editor, a free PDF editor that, when started and installed, prompts the user to accept the terms of service and privacy statement of the program.

However, the setup program secretly asks an external server to terminate the PDF editor program in the background. It also configures persistence on the host by altering the Windows Registry to make sure the downloaded executable is launched immediately upon reboot read more about TamperedChef Malware Disguised as Fake PDF Editors Steals Credentials and Cookies.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *