Skip to main content
Mallory

TamperedChef

Also known astamperedchef

TamperedChef, also known as EvilAI, is a cybercrime malware and malvertising operation that distributes trojanized productivity software masquerading as legitimate applications such as PDF editors, calendar apps, ZIP extractors, GIF makers, converters, and related utilities. Reported campaigns and variants linked in the provided content include Calendaromatic, Recipe Lister, AppSuite PDF, DocuFlex, JustAskJacky, GoCookMate, RocketPDFPro, ManualReaderPro, CrystalPDF, Easy2Convert, OneZip, PDF-Ezy, PDFPrime, ManualzPDF, and RapiDoc. Palo Alto Networks Unit 42 reported overlap across three tracked clusters: CL-CRI-1089, CL-UNK-1090, and CL-UNK-1110; the TamperedChef alias is noted as most commonly associated with CL-UNK-1110, while CL-CRI-1089 includes Calendaromatic, DocuFlex, and AppSuite PDF. The operation has been active since at least early 2023 and has been observed globally, with no strong sector-specific targeting. Distribution relies heavily on malvertising, sponsored search results, poisoned search engine results, and malicious Google and YouTube ads leading to polished download sites with legal terms, contact pages, and contextually relevant domains. The malware commonly uses valid code-signing certificates obtained through shell companies in multiple countries, including Ukraine, Malaysia, Israel, the United Kingdom, the United States, Panama, Estonia, Singapore, and Malta, although reporting also notes some operators appear to be moving away from signing. Researchers described the operation as unusually large-scale and well-funded, with thousands of samples and extensive advertising infrastructure. TamperedChef malware typically functions as advertised at first, then delays malicious activity for weeks or months. Common behaviors described in the content include persistence via scheduled tasks or Run keys, initial reconnaissance and exfiltration, continuous command-and-control for delayed second-stage delivery, and deployment of payloads including adware, browser hijackers, information stealers, remote access Trojans, proxy malware, and backdoors. Reported capabilities across associated malware include credential theft, browser session theft, remote command execution, browser hijacking, system fingerprinting, file system interaction, and environment variable exfiltration. Specific reporting in the content links TamperedChef to macOS-focused Operation FlutterBridge, attributed to CL-CRI-1089, which distributed the FlutterShell backdoor via malicious desktop applications signed with valid Apple Developer IDs and notarized by Apple at the time of submission. FlutterShell is described as a Flutter-based malware family combining adware and backdoor functionality, using a WebView and JavaScript-to-native bridge to dynamically alter behavior from remote infrastructure. Variants named PodcastsLounge, PDF-Brain, and PDF-Ninja were identified. The content also highlights Calendaromatic as a backdoor spread through malvertisements and SEO poisoning and tied to the TamperedChef malvertising campaign. Additional reporting cited in the content states TamperedChef has used Google Ads to distribute infostealers and has used U.S. shell companies to sign trojanized apps with valid certificates to deploy a stealth backdoor.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Software & Services

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States
  • 🇨🇦 Canada
  • 🇦🇺 Australia
  • 🇫🇷 France
  • 🇩🇪 Germany
MITRE ATT&CK

Tradecraft

9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

8 of 15 tactics12 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
TA0002
Execution
2 techniques
T1053
Scheduled Task/Job
T1204
User Execution
TA0003
Persistence
1 technique
T1053
Scheduled Task/Job
TA0004
Privilege Escalation
1 technique
T1053
Scheduled Task/Job
TA0005
Stealth
1 technique
T1036×2
Masquerading
TA0112
Defense Impairment
1 technique
T1553
Subvert Trust Controls
T1553.002×2
Code Signing
TA0009
Collection
1 technique
T1185
Browser Session Hijacking
TA0011
Command and Control
3 techniques
T1071×2
Application Layer Protocol
T1090
Proxy
T1105
Ingress Tool Transfer
IOCS

Observables

18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping9

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables18

Domains, IPs, and hashes tied to this actor, refreshed continuously.