Skip to main content
Mallory
Back to malware
MalwareUsed by 1 actor

Calendaromatic

Calendaromatic is a backdoor malware family that masquerades as a legitimate calendar download. It has been distributed via malvertising campaigns and SEO poisoning, and MS-ISAC also lists malvertisement as its observed initial infection vector. Reporting links Calendaromatic to the CL-CRI-1089 cybercrime cluster and to the broader TamperedChef campaign set, also known as EvilAI, which uses trojanized productivity software to deliver potentially unwanted programs (PUPs) and adware. Unit 42 linked Calendaromatic to other CL-CRI-1089 activity, including the Windows malware strain RecipeLister and the macOS FlutterShell/JSCoreRunner/FileRipple activity, based on shared infrastructure, malvertising tradecraft, and related campaign characteristics. The available content does not provide specific Calendaromatic command-and-control domains, hashes, or detailed post-infection functionality beyond its classification as a backdoor and its use of fake calendar-themed software as a lure.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
CL-CRI-1089

Operations attributed to CL-CRI-1089 also include Recipe Lister and Calendaromatic, both of which fall under a broader designation known as TamperedChef (aka EvilAI), an ongoing series of campaigns that involve using trojanized versions of productivity software to deliver potentially unwanted programs (PUPs) and adware.

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

9 distinct techniques documented for this family, organized by ATT&CK tactic.

T1583Acquire InfrastructureEvidence3

These campaigns distribute malicious Google and YouTube advertisements using a network of Google-verified shell companies, with the ads acting as a lure to trick targets into deploying malware that masquerades as legitimate desktop applications.

Execution

2 techniques
T1059Command and Scripting InterpreterEvidence1
TacticExecution

However, TamperedChef-style programs execute commands remotely, exfiltrate users' credentials and deploy malware without consent.

T1204.002Malicious FileEvidence1
TacticExecution

TamperedChef (aka EvilAI), an ongoing series of campaigns that involve using trojanized versions of productivity software to deliver potentially unwanted programs (PUPs) and adware.

Stealth

2 techniques
T1027Obfuscated Files or InformationEvidence1
TacticStealth

Most of the campaigns we observed used some form of obfuscation or defense evasion techniques for their loader or stealer components.

T1036MasqueradingEvidence2
TacticStealth

TamperedChef-style malware is trojanized productivity software, such as PDF editors or calendars, that deliver malicious payloads.

T1553.002Code SigningEvidence2

One unique attribute of the TamperedChef-style malware is that almost all the first-stage binaries are signed with legitimate code-signing certificates. Attackers used code-signing to add stealth to these payloads.

Collection

1 technique
T1185Browser Session HijackingEvidence1

Upon installation, FlutterShell fingerprints the machine... Next, the malware targets the Google Chrome “Secure Preferences” file... changing the url and new_tab_url values to the attacker-controlled domain.

T1071Application Layer ProtocolEvidence3

What makes FlutterShell noteworthy is that it implements a WebView-based architecture that utilizes a JavaScript-to-native bridge, thereby allowing the adversary to host malicious logic on an external website, rather than embedding it into the binary.

T1105Ingress Tool TransferEvidence2

Upon activation, they trigger the next stage, which typically involves downloading and executing an additional payload delivered via an upstream API.

ACTIVITY FEED

Recent activity

5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping9

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.