Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Sheryl Crow calls Trump’s UFC B-Day brawl on the White House lawn ‘disgraceful’

Normally $899.99, Roborock Qrevo S5V Robot Vacuum and Mop is $549.99 on Amazon

This lifetime AI-powered piano app teaches you as you play for $99.97 during Deal Day.

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » TamperedChef malware disguised as a fake PDF editor steals credentials and cookies
Celebrities

TamperedChef malware disguised as a fake PDF editor steals credentials and cookies

By August 29, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

August 29, 2025Ravi LakshmananMalware/Windows Security

TamperedChef Malware

Cybersecurity researchers have discovered a cybercrime campaign that uses tricks to direct victims to fraudulent sites to provide a new information steeler called TamperedChef.

“The goal is to invite victims to download and install the Trojanized PDF editor, including information-stolen malware called TamperedChef.” “Malware is designed to harvest sensitive data such as credentials and web cookies.”

At the heart of the campaign is using several fake sites to promote a free PDF editor installer called AppSuite PDF Editor.

However, in the background, the setup program makes a secret request to an external server, drops the PDF editor program, and at the same time makes changes to the Windows registry to set up host persistence by verifying that the downloaded executable file will automatically start after a reboot. The registry key contains the -CM argument parameters to pass instructions to the binary.

Cybersecurity

Also, German cybersecurity company G Data, which analyzed the activity, said that various websites that provide these PDF editors download the same setup installer and download the PDF editor program from the server once the user accepts the license agreement.

“Next, we’ll run the main applications without discussion. This is equivalent to starting the -install routine,” said security researchers Karsten Hahn and Louis Solita. “We’ll also create an Autorun entry that provides command line arguments – CM = -FullUpDate running the following malicious application.”

The campaign is rated as being launched on June 26, 2025, when many of the counterfeit sites began registering or promoting their PDF editing software through at least five different Google Ads campaigns.

“In the beginning, the PDF appears to be working almost harmlessly, but the code includes steps to periodically check for potential updates to .JS files containing the -CM argument,” the researchers explained. “From August 21, 2025, the machine that recalled received instructions to enable a malicious feature called “TamperedChef” that is information stealing. ”

Once initialized, the Steeler will collect a list of installed security products and attempt to close the web browser to access sensitive data such as credentials and cookies.

Further analysis of malware-covered applications with G Data revealed that it acts as a backdoor and supports many features –

– Install, create a scheduled task named PDFEDITORSCHEDULEDTASK, and create a pdfeditoruscheduledtask that runs the application using the -cm=-partialUpdate and -cm=-backupupdate arguments. Delete two scheduled tasks – ping, communicating with command and control (C2) of actions to be performed on the system. This allows for malware downloads, data removal, and registry changes, among other things – checks, contacting C2 server configuration, read browser keys, set browsers, and run any commands and run any commands. Check with Chrome, OneLaunch, and Wave browsers, credentials, browser history, cookies, or settings custom search engines (reboot, same) and the ability to kill certain processes

Identity Security Risk Assessment

“Length since the start [ad] The malicious update is also 56 days, a campaign that is close to the 60-day length of a typical Google Ads campaign, suggesting that threat actors run ad campaigns, maximize downloads, and activate malicious features,” Truesec said.

This disclosure coincides with an analysis from Expel that details ads to ads ads that serve users ads that provide downloads of tools such as AppSuite, PDF Onestart, and PDF Editor. In some cases, these PDF programs are known to download other Trojanized apps or turn hosts into residential proxy without the consent of the user.

“The AppSuite PDF Editor is malicious,” says G Data. “This is a classic Trojan horse with a backdoor that is currently being downloaded at a large scale.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleTrump administration deals are structured to prevent Intel from selling casting units
Next Article Invicta Water: Addresses PFAS Environmental Pollution

Related Posts

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

June 15, 2026

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Sheryl Crow calls Trump’s UFC B-Day brawl on the White House lawn ‘disgraceful’

Normally $899.99, Roborock Qrevo S5V Robot Vacuum and Mop is $549.99 on Amazon

This lifetime AI-powered piano app teaches you as you play for $99.97 during Deal Day.

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

Trending Posts

Sheryl Crow calls Trump’s UFC B-Day brawl on the White House lawn ‘disgraceful’

June 16, 2026

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

June 16, 2026

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

June 16, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.