CL-UNK-1090 is a malware distribution cluster associated with large-scale TamperedChef or EvilAI-style activity involving trojanized productivity software. The cluster is notable for apparent vertical integration between malware operations and advertising infrastructure, with the same ecosystem controlling front-end ad agencies and back-end shell companies used for code signing and distribution. It has been linked primarily to Israeli infrastructure and corporate entities. The cluster distributes malicious software disguised as legitimate business tools such as PDF utilities, file conversion tools, compression software, and similar workflow applications. Campaigns associated with CL-UNK-1090 include CrystalPDF, Easy2Convert, PDF-Ezy, and OneZip. The lures are presented through polished, legitimate-looking websites with business-style documentation and legal pages, and distribution relies heavily on malvertising, sponsored search placement, and large-scale search engine marketing abuse. More than 20,000 unique advertisements have been attributed to this cluster over multiple years, indicating substantial operational scale and investment. CL-UNK-1090 has used legitimate code-signing certificates obtained through corporate structures to increase trust and reduce security friction, although operators have reportedly shifted away from heavy reliance on code signing as signer-based tracking improved. The cluster also uses generative AI and large language models to create large numbers of landing-page variants, complicating simple signature and hash-based detection. Operationally, the trojanized applications often provide the advertised functionality at first, then delay malicious behavior for weeks or months to evade sandboxing and casual inspection. After activation, they retrieve second-stage payloads that can include information stealers, remote access Trojans, browser hijackers, adware, and proxy tooling. CL-UNK-1090 has been described as favoring stealthier in-memory payload delivery that leaves fewer artifacts on disk. Observed behavior across TamperedChef-style activity includes persistence, reconnaissance, exfiltration, arbitrary code execution through downloaded modules, and post-compromise delivery of additional malware. Victimization is global and not strongly sector-specific, with somewhat higher observed volumes in Israel and the United States. The cluster appears financially resourced and operationally mature, combining advertising logistics, malware development, shell-company administration, and evasive delivery techniques into a unified distribution model.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Infrastructure cluster tied to large-scale malvertising and trojanized software distribution, with vertically integrated control over ad agencies and code-signing shell companies to support malware delivery.
A TamperedChef activity cluster tied to CrystalPDF, OneZip, RapiDoc, and related campaigns, characterized by vertically integrated ad distribution and signing infrastructure, large-scale advertising, and stealthy in-memory payloads.
A TamperedChef-style cluster characterized by vertical integration between advertising and malware creation. It distributes malicious productivity apps via malvertising, uses primarily Israeli infrastructure and code-signing entities, and is linked through FireArc-related corporate structures. Second stages observed include stealthy in-memory RATs, browser hijackers, and adware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.