TamperedChef, also known as EvilAI, is a large-scale cybercrime operation centered on trojanized productivity applications distributed through malvertising, poisoned search results, and sponsored advertisements. Active since at least 2023, the operation has used fake but functional software such as PDF tools, calendar apps, archive utilities, converters, and similar desktop applications to lure victims into installing malware that initially appears legitimate. Security reporting has linked the activity to multiple overlapping clusters, notably CL-CRI-1089, CL-UNK-1090, and CL-UNK-1110, with campaigns including Calendaromatic, Recipe Lister, AppSuite PDF, DocuFlex, CrystalPDF, OneZip, Easy2Convert, JustAskJacky, GoCookMate, RocketPDFPro, ManualReaderPro, PDFPrime, ManualzPDF, and RapiDoc. Some reporting also describes Operation FlutterBridge as part of the broader TamperedChef or EvilAI ecosystem on macOS. The operation is characterized by professionally built lure sites, extensive advertising infrastructure, and widespread abuse of legitimate code-signing certificates obtained through shell companies in multiple jurisdictions. Researchers have documented thousands of samples and more than one hundred variants, indicating an unusually well-resourced and industrialized malware distribution ecosystem. Some clusters appear to control both malware development and advertising operations, suggesting vertical integration between traffic acquisition, software packaging, and payload delivery. TamperedChef commonly relies on signed first-stage binaries, delayed activation, and staged payload delivery to reduce suspicion and evade detection. The bundled applications often work as advertised while malicious functionality remains dormant for weeks or months. Across observed campaigns, first-stage malware has established persistence, performed host reconnaissance, contacted command-and-control infrastructure, and retrieved second-stage payloads. Documented follow-on payloads include information stealers, remote access Trojans, browser hijackers, adware, proxy malware, and backdoors. Reported capabilities include credential theft, browser session theft, command execution, file-system interaction, environment and system fingerprinting, exfiltration, persistence, and browser hijacking. Some variants have modified browser configuration to redirect traffic through attacker-controlled intermediaries, while others have used in-memory or dynamically delivered logic to minimize on-disk artifacts. A notable macOS branch associated with CL-CRI-1089 used Flutter-based malware known as FlutterShell, delivered through malicious desktop applications and signed with valid Apple Developer IDs that passed notarization at the time of observation. That malware combined adware and backdoor behavior, including arbitrary command execution, file access, environment-variable exfiltration, browser hijacking, system fingerprinting, and theft of browser session data. Its WebView and JavaScript-to-native bridge architecture allowed operators to change behavior remotely without recompiling the binary. Victimology is broad and largely opportunistic rather than sector-specific, with global infections observed across enterprise environments. High-confidence reporting specifically identifies targeting of users in the United States, Canada, Australia, France, and Germany, and notes somewhat elevated activity in Israel and the United States in broader telemetry. The dominant motivation is financial, reflected in the use of malvertising, adware, infostealers, browser hijackers, and monetizable access or traffic-redirection schemes rather than espionage objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as an example of a threat actor known to abuse code-signing certificates.
A broader campaign designation covering ongoing operations that use trojanized productivity software to deliver PUPs and adware, associated with CL-CRI-1089.
Operates large-scale malware campaigns using trojanized productivity applications that appear legitimate, leveraging signed software, fake download sites, delayed second-stage payload delivery, credential theft, RAT deployment, adware/browser hijacking, and proxy-style malware.
A broad label for malicious productivity-software campaigns using trojanized apps, malvertising, signed binaries, dormancy, C2 retrieval of second-stage payloads, and delivery of stealers, proxy tools, RATs, adware, and browser hijackers. The article explicitly notes TamperedChef is not attributed to a single author or group.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.