TamperedChef malware is hiding inside signed productivity apps
Security researchers are warning about TamperedChef, a broad set of malware campaigns that hide malicious code inside everyday productivity apps. The apps often look useful, install normally, and may even perform the function they advertise.
The threat is serious because many of these apps use valid code-signing certificates. That can make them appear more trustworthy to users and some security tools, even when they can later deliver infostealers, remote access trojans, adware, or proxy-style payloads.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
Unit 42 researchers tracked three major TamperedChef-style activity clusters and found more than 4,000 samples across 100 unique variants. The campaigns include fake or trojanized PDF editors, ZIP tools, calendar apps, GIF makers, file converters, and other utility software.
What TamperedChef malware does
TamperedChef is also known as EvilAI in some reporting. It is not a single app or one simple malware family. Instead, researchers use the name to describe several related campaigns that share similar tactics, including signed installers, professional-looking download pages, and delayed malicious behavior.
These apps can stay quiet for weeks or months before activating more harmful features. That delay helps the attackers avoid early suspicion because the user may have already accepted the app as legitimate.
Once active, the malware can collect system information, steal credentials, run commands, deploy second-stage payloads, hijack browser behavior, or route traffic through infected machines.
Why signed apps make the campaign harder to spot
Code signing normally helps confirm that software came from a known publisher and was not changed after signing. Attackers abuse that trust by obtaining certificates through networks of companies or related business entities.
Unit 42 said it tracked 81 unique code-signing organizations tied to TamperedChef-style activity. In one cluster, the researchers linked 34 code-signing entities to Calendaromatic-related activity alone.
The signed apps also use convincing websites. Many include legal pages, contact pages, clean branding, and simple download buttons. For a normal user, the experience can look similar to downloading a legitimate free productivity tool.
| Campaign trait | How attackers use it | Why it works |
|---|---|---|
| Valid code signing | Apps are signed with legitimate certificates. | Users and tools may treat the software as safer than unsigned files. |
| Working app features | The app may perform the promised task. | Victims have less reason to uninstall it quickly. |
| Delayed activation | Malicious features may appear weeks later. | Security teams may miss the link to the original install. |
| Malvertising | Campaigns use ads to drive users to download sites. | Attackers can reach large numbers of users quickly. |
| Second-stage payloads | The app can fetch additional malware later. | Attackers can change payloads without replacing the first installer. |
Unit 42 tracked three major clusters
Unit 42 separates the activity into three major clusters: CL-CRI-1089, CL-UNK-1090, and CL-UNK-1110. The groups share many tactics, but the researchers said they likely represent distinct operators rather than one single actor.
CL-CRI-1089 includes campaigns such as Calendaromatic, DocuFlex, and AppSuite PDF. Unit 42 said this cluster has been active since early 2023 and uses varied delivery methods, infrastructure, and code-signing entities.
CL-UNK-1090 includes campaigns such as CrystalPDF, Easy2Convert, and PDF-Ezy. Researchers said this cluster stands out because it shows links between marketing infrastructure and malware delivery, including large-scale advertising activity.
How the malware spreads
TamperedChef-style campaigns often begin with ads or search-driven downloads. Users see a tool that promises to edit PDFs, convert files, extract ZIP archives, or perform another common productivity task.
After installation, the software may contact remote infrastructure for configuration, updates, or new payloads. Some versions use scheduled tasks or registry Run keys to maintain persistence after reboot.
Truesec previously documented AppSuite PDF Editor activity where the software appeared mostly harmless at first, then later activated malicious information-stealing behavior. That pattern matches the broader concern around delayed activation in these campaigns.
- PDF editors and PDF converters
- ZIP extractors and archive tools
- Calendar apps
- GIF and image tools
- File conversion utilities
- Search assistant apps
- Manual reader tools
Why businesses should treat this as more than adware
Some TamperedChef-style apps may look like unwanted software at first. Unit 42 warned that this understates the risk because the apps can execute commands remotely, exfiltrate credentials, and deploy other malware without consent.
The scale also matters. Unit 42 found evidence of CL-CRI-1089 and CL-UNK-1090 across more than half of its Managed Threat Hunting customers. The company said that, if the data reflects the wider community, the operation shows a rare level of reach.
The campaigns also show how attackers can blend cybercrime with advertising and software distribution. In CL-UNK-1090, Unit 42 identified more than 20,000 unique ads deployed over several years through ad transparency platforms.
| Cluster | Examples named by researchers | Notable detail |
|---|---|---|
| CL-CRI-1089 | Calendaromatic, DocuFlex, AppSuite PDF | Linked to early activity and many code-signing entities. |
| CL-UNK-1090 | CrystalPDF, Easy2Convert, PDF-Ezy | Shows strong links between advertising operations and malware delivery. |
| CL-UNK-1110 | JustAskJacky, GoCookMate, RocketPDFPro, ManualReaderPro | Often associated with the TamperedChef alias in public reporting. |
How users and security teams can reduce the risk
Users should avoid downloading free productivity apps from unfamiliar websites, especially when the tool appears through an ad or a search result rather than a trusted vendor page. A signed installer does not guarantee that an app is safe.
Businesses should restrict software installation rights and maintain an approved software catalog. Security teams should also monitor for suspicious scheduled tasks, registry Run keys, unusual outbound traffic, browser credential access, and unexpected second-stage payload downloads.
If a suspicious productivity app is found, the safest response is to isolate the affected device, remove persistence entries, reset exposed credentials, and review account logs for signs of misuse.
- Download software only from known vendor websites or trusted app stores.
- Be cautious with free tools promoted through ads.
- Check publisher names, domains, and installer behavior before deployment.
- Block unknown software installations on managed devices.
- Monitor endpoints for delayed payload downloads and suspicious persistence.
- Reset credentials if a device may have run an infostealer.
FAQ
TamperedChef is a name used for several malware campaigns that disguise malicious code inside productivity apps. These apps may look legitimate, work normally at first, and later deploy infostealers, remote access trojans, adware, or other payloads.
Signed apps can look more trustworthy because they carry valid code-signing certificates. Attackers abuse that trust by signing malicious or trojanized software, which can make users and some security tools less suspicious.
Researchers have linked TamperedChef-style activity to PDF editors, file converters, ZIP tools, calendar apps, GIF makers, search assistants, and manual reader apps. These tools often appear useful while hiding malicious behavior.
Download productivity tools only from trusted vendors or official app stores. Avoid unknown free tools promoted through ads, check the publisher carefully, and do not rely on a digital signature alone as proof that software is safe.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages