Malware Campaign

Cyber Security News by CyberSum.net
2 sources
A sophisticated malware campaign dubbed TamperedChef is exploiting trojanized productivity tools to bypass security controls, establish persistence, and siphon sensitive information from targeted systems, the campaign uses malicious advertising and fully functional decoy software to infiltrate corporate networks, the malware is disguised as a legitimate PDF editor and is distributed through sponsored search engine ads, once installed, the malware adds persistence mechanisms and creates autorun registry entries, ensuring it launches automatically at system logon, the malware uses a custom NodeJS module to manipulate registry keys and create scheduled tasks for persistence, it communicates with attacker-owned domains to retrieve additional payloads and exfiltrate sensitive data.