A sophisticated malvertising operation has weaponized a seemingly legitimate PDF editing application to distribute the TamperedChef infostealer, compromising over 100 organizations across 19 countries.
Managed Detection and Response teams discovered the campaign in September 2025, revealing a 56-day dormancy period designed to maximize infections before activation.
The campaign, believed to be part of the broader EvilAI operation, began on June 26, 2025, with threat actors registering multiple domains to promote the trojanized AppSuite PDF Editor via Google Ads and search-engine optimization poisoning.
The malicious application appeared fully functional to victims but silently deployed credential-stealing capabilities targeting Windows systems.
Global Impact and Victim Profile
Telemetry identified victims across 19 nations, with Germany accounting for approximately 15% of infections, followed by the United Kingdom at 14% and France at 9%.
Rather than deliberate geographic targeting, researchers believe the distribution reflects the campaign’s widespread global reach through paid advertising platforms.
Industries that rely heavily on specialized technical equipment experienced a disproportionate impact, likely because employees frequently search online for product manuals, a behavior the TamperedChef operators actively exploited through malicious advertisements on legitimate manual library websites.
The attack chain typically begins when users search for appliance manuals or PDF editing software.
Malicious Google Ads redirect victims to deceptive domains such as fullpdf[.]com and pdftraining[.]com, where they download the Appsuite PDF.msi installer.

Upon execution, the installer deploys PDFEditorSetup.exe and a heavily obfuscated JavaScript file (pdfeditor.js) that researchers suspect contains AI-generated code to evade signature-based detection.

The malware establishes persistence by modifying the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\PDFEditorUpdater registry key and creating scheduled tasks with specific command-line flags, including –install, –fullupdate, and –check.
The installed PDF Editor.exe binary first enumerates security products from vendors, including Bitdefender, Check Point, Fortinet, G DATA, Kaspersky, and Zillya, via registry queries.
It then terminates browser processes and leverages the Windows Data Protection API to extract stored credentials, cookies, and autofill data.
A secondary payload, ManualFinderApp.exe, provides backdoor functionality and communicates with the command-and-control infrastructure, including the portal. manualfinder[.]app and mka3e8[.]com.
The campaign’s sophistication extends to the deliberate acquisition or compromise of legitimate code-signing certificates issued by Malaysian and American entities, including ECHO Infini SDN. BHD, GLINT by J SDN. BHD, and SUMMIT NEXUS Holdings LLC.

According to Sophos, these certificates bypass Windows SmartScreen protections and establish false trust with potential victims.
While authorities have revoked the observed certificates, researchers warn that threat actors may acquire additional signing credentials.
The 56-day delay between installation and payload activation reflects a calculated strategy rather than a technical limitation.
This timeframe aligns precisely with typical 30-60 day advertising campaign durations, allowing operators to maximize infected endpoints before triggering malicious behavior that would alert security vendors.
Organizations should treat all browser-stored credentials on affected systems as compromised and implement immediate password resets, coupled with multi-factor authentication enforcement.
Security teams should monitor for suspicious scheduled tasks that execute from user profile directories and use GUID-like task names, such as sys_component_health_bb1b47cb-962f-fb06-4b84-87ad12b4f37f8de0, which mimic legitimate Windows maintenance processes.
MITRE
| Activity | Attack Tactic | Attack Technique |
|---|---|---|
| Malvertising on search engines (Google/Bing) and malicious lures that redirect users to malicious sites (e.g., fullpdf[.]com, pdftraining[.]com) | Initial Access | T1189 — Drive-by Compromise |
| AppSuite-PDF.msi drops PDFEditorSetup.exe (installer staging) | Persistence | T1105 — Ingress Tool Transfer |
| PDFEditorSetup.exe creates registry and scheduled task entries | Persistence | T1053.005 — Scheduled Task/Job: Scheduled Task |
| PDFEditorSetup.exe installs PDF Editor.exe (final payload) | Execution | T1204.002 — User Execution (installed binary) / T1106 — Native API |
| PDF Editor.exe steals/modifies browser-stored data (credentials, cookies, autofill) | Credential Access | T1555.003 — Credentials from Web Browsers and T1005 — Data from Local System |
| PDF Editor.exe connects to C2 domain(s) (HTTP/S) for exfiltration and remote control | Command and Control / Exfiltration | T1071.001 — Application Layer Protocol: Web Protocols (HTTP/S) and T1041 — Exfiltration Over C2 Channel |
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.