{"id":9990,"date":"2026-01-20T10:03:40","date_gmt":"2026-01-20T10:03:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/20\/threat-actors-leverage-google-ads-to-weaponize-pdf-editor-with-tamperedchef\/"},"modified":"2026-01-20T10:03:40","modified_gmt":"2026-01-20T10:03:40","slug":"threat-actors-leverage-google-ads-to-weaponize-pdf-editor-with-tamperedchef","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/20\/threat-actors-leverage-google-ads-to-weaponize-pdf-editor-with-tamperedchef\/","title":{"rendered":"Threat Actors Leverage Google Ads to Weaponize PDF Editor with TamperedChef"},"content":{"rendered":"<p>    Threat Actors Leverage Google Ads to Weaponize PDF Editor with TamperedChef<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A malvertising campaign identified in September 2025 has brought a significant threat to Windows users worldwide. <\/p>\n<p>Attackers created fake PDF editing applications and promoted them through Google Ads to distribute a dangerous information-stealing malware called TamperedChef. <\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> targets users searching for appliance manuals and PDF editing tools online, exploiting common search behaviors to deliver silent infections across multiple industries and regions.<\/p>\n<p>The campaign began officially on June 26, 2025, when threat actors registered multiple look-alike websites promoting a trojanized application named <a href=\"https:\/\/cybersecuritynews.com\/appsuite-pdf-editor-hacked\/\" target=\"_blank\" rel=\"noreferrer noopener\">AppSuite<\/a> PDF Editor. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi7jO9dfw5ObJyC4Nxp0fGiai3ViqtYZcDueRrFMYEd_pAPG5UvYk2ghs2PpogW41euZ1AMPc-lu2HFC3OmPak6biMsGqBLZ2WY2Yi5T3rluZN4e8ZuUrxcYHILEeYW2IRQYKhhng0VcniOAPNXawWL3MmtzPSW5Ezi0ud-WTDZzDJtn-QgwRQCxez4hKs\/s16000\/Timeline%2520of%2520the%2520TamperedChef%2520campaign%2520%28Source%2520-%2520Sophos%29.webp?ssl=1\" alt=\"Timeline of the TamperedChef campaign (Source - Sophos)\"><figcaption class=\"wp-element-caption\">Timeline of the TamperedChef campaign (Source \u2013 Sophos)<\/figcaption><\/figure>\n<\/div>\n<p>Users believed they were downloading legitimate software, but the installer actually contained hidden malicious code designed to steal sensitive browser data. <\/p>\n<p>What makes this attack particularly deceptive is its timing\u2014the malware remained dormant for approximately 56 days, matching typical advertising campaign cycles. <\/p>\n<p>This strategic delay allowed the malware to infect as many devices as possible before displaying harmful behavior.<\/p>\n<p>Sophos analysts and researchers <a href=\"https:\/\/www.sophos.com\/en-us\/blog\/tamperedchef-serves-bad-ads-with-infostealers-as-the-main-course\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the malware after discovering over 100 affected customer systems during their managed detection and response operations. <\/p>\n<p>Their investigation revealed that victims primarily came from Germany, the United Kingdom, and France, though the campaign affected at least 19 countries globally. <\/p>\n<p>The attackers targeted industries relying on specialized equipment, where employees frequently search for product manuals online\u2014a behavior the threat actors exploited systematically to spread their malicious installer.<\/p>\n<h2 class=\"wp-block-heading\" id=\"the-silent-infection-how-tamperedchef-operates\"><strong>The Silent Infection: How TamperedChef Operates<\/strong><\/h2>\n<p>The infection mechanism of TamperedChef demonstrates sophisticated multi-stage deployment tactics designed to evade detection. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgHR5jmuW0d_GbJcqeyeUsNR5CU-8MNnsQm7gJTtwUpabgO3iQiXXj0oXW75P4q1nwFDnqADPG2SYdI9dnsKu0JBfqs8ubg2HbzdVMLgO5fSONQBNA-Llt8mnRGv6jsXh9w-xDs6tfaBj2iVWl3TelLpPeAykD6tXvW4ZxeZAJ8-i21LgBLasWGfdBko_E\/s16000\/The%2520TamperedChef%2520attack%2520chain%2520%28Source%2520-%2520Sophos%29.webp?ssl=1\" alt=\"The TamperedChef attack chain (Source - Sophos)\"><figcaption class=\"wp-element-caption\">The TamperedChef attack chain (Source \u2013 Sophos)<\/figcaption><\/figure>\n<\/div>\n<p>Users begin by clicking malicious advertisements appearing in search results on platforms like Google and Bing. <\/p>\n<p>These ads direct them to deceptive websites such as fullpdf.com and pdftraining.com, where they download the Appsuite-PDF.msi installer. <\/p>\n<p>Once executed, this file drops a setup executable called PDFEditorSetup.exe along with an <a href=\"https:\/\/cybersecuritynews.com\/highly-obfuscated-net-sectoprat\/\" target=\"_blank\" rel=\"noreferrer noopener\">obfuscated<\/a> JavaScript file and an additional executable. <\/p>\n<p>PDFEditorSetup.exe then silently establishes persistence by creating registry entries and Windows scheduled tasks, ensuring the malware survives system restarts. <\/p>\n<p>Finally, the installer deploys PDF Editor.exe, the actual infostealer component, which awakened on August 21, 2025, to begin harvesting browser credentials, cookies, and autofill data. <\/p>\n<p>The attackers further enhanced their operation by abusing legitimate code-signing certificates from Malaysian and US-registered entities, enabling their malicious files to bypass Windows <a href=\"https:\/\/cybersecuritynews.com\/windows-smartscreen-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">SmartScreen<\/a> protections and appear trustworthy to unsuspecting users. <\/p>\n<p>This layered infection process showcases how modern threat actors combine <a href=\"https:\/\/cybersecuritynews.com\/new-malvertising-campaign\/\" target=\"_blank\" rel=\"noreferrer noopener\">malvertising<\/a>, legitimate-looking software interfaces, and system-level evasion techniques to maximize infection success and minimize early detection.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-leverage-google-ads\/\">Threat Actors Leverage Google Ads to Weaponize PDF Editor with TamperedChef<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/threat-actors-leverage-google-ads\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat Actors Leverage Google Ads to Weaponize PDF Editor with TamperedChef A malvertising campaign identified in September 2025 has brought a significant threat to Windows users worldwide. Attackers created fake PDF editing applications and promoted them through Google Ads to distribute a dangerous information-stealing malware called TamperedChef. The malware targets users searching for appliance manuals [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-9990","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9990"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9990"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9990\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9990"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9990"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9990"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}