TamperedChef, also referred to as EvilAI and tracked in one activity cluster as CL-UNK-1110, is a large-scale malware distribution operation centered on trojanized productivity software. The operation has used fake but functional applications such as PDF tools, calendar utilities, archive tools, converters, and similar desktop software to lure victims into installing malware. Known CL-UNK-1110-associated campaigns include JustAskJacky, GoCookMate, RocketPDFPro, and ManualReaderPro. The operation relies heavily on malvertising, sponsored search results, and professionally built download sites designed to resemble legitimate software vendors. Operators have used valid code-signing certificates and polished branding to reduce suspicion and improve execution success. A notable tradecraft feature is delayed activation: the installed application often works as advertised while malicious functionality remains dormant for weeks or months, complicating detection and attribution. TamperedChef commonly establishes persistence, performs host reconnaissance, and retrieves second-stage payloads through ongoing command-and-control communications. Observed follow-on payloads have included information stealers, remote access Trojans, browser hijackers, adware, and proxy malware. Across the broader TamperedChef activity, payloads have supported credential theft, remote command execution, traffic redirection, and stealthy post-compromise access. Researchers have also identified multiple related clusters, including CL-CRI-1089 and CL-UNK-1090, indicating an ecosystem rather than a single narrowly scoped campaign. Victimization has been global with no strong evidence of narrow sector-specific targeting. The activity appears financially resourced and operationally mature, with emphasis on scalable distribution, evasive delivery, and monetizable second-stage malware rather than espionage or destructive effects.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A TamperedChef activity cluster mentioned as one of three tracked clusters; the content links it to the JustAskJacky campaign but provides limited operational detail.
A TamperedChef-associated cluster tied to campaigns such as JustAskJacky, GoCookMate, RocketPDFPro, and ManualReaderPro. The article identifies it as active and significant but does not focus on it in depth.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.