Threat Actors Leverage Google Ads to Promote PDF Editor Weaponized With TamperedChef

A sophisticated malvertising operation has weaponized a seemingly legitimate PDF editing application to distribute the TamperedChef infostealer, compromising over 100 organizations across 19 countries.

Managed Detection and Response teams discovered the campaign in September 2025, revealing a 56-day dormancy period designed to maximize infections before activation.

The campaign, believed to be part of the broader EvilAI operation, began on June 26, 2025, with threat actors registering multiple domains to promote the trojanized AppSuite PDF Editor via Google Ads and search-engine optimization poisoning.

The malicious application appeared fully functional to victims but silently deployed credential-stealing capabilities targeting Windows systems.​

Global Impact and Victim Profile

Telemetry identified victims across 19 nations, with Germany accounting for approximately 15% of infections, followed by the United Kingdom at 14% and France at 9%.

Rather than deliberate geographic targeting, researchers believe the distribution reflects the campaign’s widespread global reach through paid advertising platforms.​

Industries that rely heavily on specialized technical equipment experienced a disproportionate impact, likely because employees frequently search online for product manuals, a behavior the TamperedChef operators actively exploited through malicious advertisements on legitimate manual library websites.​

The attack chain typically begins when users search for appliance manuals or PDF editing software.

Malicious Google Ads redirect victims to deceptive domains such as fullpdf[.]com and pdftraining[.]com, where they download the Appsuite PDF.msi installer.

 AppSuite advert
 AppSuite advert (Source: Sophos)

Upon execution, the installer deploys PDFEditorSetup.exe and a heavily obfuscated JavaScript file (pdfeditor.js) that researchers suspect contains AI-generated code to evade signature-based detection.

PDF Editor setup
PDF Editor setup (Source: Sophos)

The malware establishes persistence by modifying the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\PDFEditorUpdater registry key and creating scheduled tasks with specific command-line flags, including –install, –fullupdate, and –check.

The installed PDF Editor.exe binary first enumerates security products from vendors, including Bitdefender, Check Point, Fortinet, G DATA, Kaspersky, and Zillya, via registry queries.

It then terminates browser processes and leverages the Windows Data Protection API to extract stored credentials, cookies, and autofill data.

A secondary payload, ManualFinderApp.exe, provides backdoor functionality and communicates with the command-and-control infrastructure, including the portal. manualfinder[.]app and mka3e8[.]com.

The campaign’s sophistication extends to the deliberate acquisition or compromise of legitimate code-signing certificates issued by Malaysian and American entities, including ECHO Infini SDN. BHD, GLINT by J SDN. BHD, and SUMMIT NEXUS Holdings LLC.

PDF Editor.exe certificate details
PDF Editor.exe certificate details (Source: Sophos)

According to Sophos, these certificates bypass Windows SmartScreen protections and establish false trust with potential victims.

While authorities have revoked the observed certificates, researchers warn that threat actors may acquire additional signing credentials.

The 56-day delay between installation and payload activation reflects a calculated strategy rather than a technical limitation.

This timeframe aligns precisely with typical 30-60 day advertising campaign durations, allowing operators to maximize infected endpoints before triggering malicious behavior that would alert security vendors.

Organizations should treat all browser-stored credentials on affected systems as compromised and implement immediate password resets, coupled with multi-factor authentication enforcement.

Security teams should monitor for suspicious scheduled tasks that execute from user profile directories and use GUID-like task names, such as sys_component_health_bb1b47cb-962f-fb06-4b84-87ad12b4f37f8de0, which mimic legitimate Windows maintenance processes.

MITRE

ActivityAttack TacticAttack Technique
Malvertising on search engines (Google/Bing) and malicious lures that redirect users to malicious sites (e.g., fullpdf[.]com, pdftraining[.]com)Initial AccessT1189 — Drive-by Compromise
AppSuite-PDF.msi drops PDFEditorSetup.exe (installer staging)PersistenceT1105 — Ingress Tool Transfer
PDFEditorSetup.exe creates registry and scheduled task entriesPersistenceT1053.005 — Scheduled Task/Job: Scheduled Task
PDFEditorSetup.exe installs PDF Editor.exe (final payload)ExecutionT1204.002 — User Execution (installed binary) / T1106 — Native API
PDF Editor.exe steals/modifies browser-stored data (credentials, cookies, autofill)Credential AccessT1555.003 — Credentials from Web Browsers and T1005 — Data from Local System
PDF Editor.exe connects to C2 domain(s) (HTTP/S) for exfiltration and remote controlCommand and Control / ExfiltrationT1071.001 — Application Layer Protocol: Web Protocols (HTTP/S) and T1041 — Exfiltration Over C2 Channel

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories