Threats Tagged 'tamperedchef'
View all threats tagged with 'tamperedchef'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'tamperedchef'
Click on any threat for detailed analysis and mitigation recommendations
Projextor is a malware campaign that leverages Electron-based productivity applications to deliver malicious payloads. The threat disguises itself as legitimate document converters, meal planners, and PDF management tools with working user interfaces. Distribution occurs through impersonating websites that mimic genuine services, using high-ranking search results to lure victims. Applications like Kitchen Canvas, Food Formula, DocConvertWizard, and PDFGrip contain insecure Electron configurations that enable dynamic JavaScript execution and desktop capture capabilities. The infection chain begins with NSIS, Squirrel, or Inno Setup installers that download the main Electron application. Preload scripts abuse privileged Node.js APIs with intentionally disabled security features, allowing arbitrary code execution and screen monitoring. This enables threat actors to capture sensitive information, monitor user activity, and execute remote commands while maintaining the appearance of functional productivity soft... Join the discussion | AlienVault OTX General | 08/17/2026, 15:16:22 UTC Added: 08/18/2026, 09:26:43 UTC |
This threat involves three advanced browser hijacking techniques targeting Firefox and Chrome browsers. The first technique modifies browser preference files directly to alter settings such as default search engines and homepage configurations. The second, known as BRAT (Browser Remote Access Tool), remotely simulates key presses to manipulate browser behavior, including opening unwanted tabs and changing search engines. The third exploits a Chromium command line switch to load malicious extensions while disabling browser updates to maintain persistence. These methods enable attackers to control browser behavior stealthily, potentially leading to user tracking, ad fraud, or further malware deployment. Although no known exploits are currently active in the wild, the techniques demonstrate evolving sophistication in browser hijacking. The threat is rated medium severity due to its potential impact on user privacy and browser integrity, combined with moderate exploitation complexity. European organizations relying heavily on Chrome and Firefox browsers should be vigilant, as these browsers are widely used across the continent. Detection and mitigation require enhanced monitoring of browser configuration files, command line parameters, and unusual input simulation activities. Proactive measures are essential to prevent persistent hijacking and maintain browser security integrity. Join the discussion | AlienVault OTX General | 12/10/2025, 19:31:46 UTC Added: 12/11/2025, 09:08:56 UTC |
A large cybercrime campaign has been observed involving multiple fraudulent websites promoted through Google advertising. The campaign aims to trick users into downloading and installing a trojanized PDF editor containing the TamperedChef information-stealing malware. The malware harvests sensitive data, including credentials and web cookies. The campaign began on June 26, 2025, with the PDF editor initially appearing harmless but later activating malicious capabilities. The threat actor used Google advertising to promote the PDF editor, with at least 5 different campaign IDs observed. The malware's activation occurred 56 days after the campaign's start, coinciding with a typical Google ad campaign duration. The threat actor has a history of distributing malicious code disguised as free utility tools, and this campaign has successfully affected several European organizations. Join the discussion | AlienVault OTX General | 08/28/2025, 13:34:18 UTC Added: 08/28/2025, 13:47:48 UTC |
Trojan horses, once rare, are making a resurgence due to AI and Large Language Models (LLMs). These new trojans, disguised as legitimate applications like recipe apps or AI-powered image search tools, are evading traditional security measures. They appear professional, pass VirusTotal scans, and exploit users' trust. Examples include JustAskJacky, which executes hidden commands, and TamperedChef, which hides malicious code in recipe whitespace. LLMs enable threat actors to create convincing websites and functional applications easily, making trojans indistinguishable from legitimate software. This trend challenges conventional user caution and static antivirus scanning, necessitating advanced security measures like context, behavior, and dynamic analysis for detection. Join the discussion | AlienVault OTX General | 08/13/2025, 10:55:03 UTC Added: 08/13/2025, 15:17:48 UTC |
Showing 1 to 4 of 4 results