Threat actors are increasingly leveraging fake websites and bogus software installers to distribute malware, employing advanced techniques such as AI-generated web pages and code-signed malicious applications. One campaign involves the use of the legitimate Syncro remote access tool, where attackers create their own signed builds and distribute them via mass-generated, AI-powered fake websites that closely mimic official application sites. These malicious sites are promoted through search engine optimization and phishing emails, often masquerading as trusted brands like antivirus or password management tools, to trick users into downloading malware-laden installers.
Another ongoing global campaign, dubbed TamperedChef, uses counterfeit installers for popular software to deliver JavaScript-based remote access malware. The attackers utilize malvertising, SEO, and abused digital certificates from shell companies to increase the credibility of their malicious payloads. The infrastructure supporting these campaigns is described as industrialized, with operators regularly acquiring new code-signing certificates to evade detection. Both campaigns highlight the growing sophistication and scale of malvertising operations targeting users through deceptive download sites and installer packages.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Reporting revealed that the operation cycled code-signing certificates linked to shell companies in multiple countries, including U.S. shell companies, to keep trojanized applications appearing legitimate as older certificates were revoked. This highlighted the campaign's industrialized infrastructure and certificate abuse at scale.
Acronis Threat Research Unit reported that the fake installer drops an XML file that creates a scheduled task, which then launches an obfuscated JavaScript backdoor. The malware beacons over HTTPS and sends encrypted, Base64-encoded JSON containing host identifiers and system metadata.
An ongoing campaign dubbed TamperedChef used malvertising, SEO poisoning, and bogus software installers signed with valid code-signing certificates to trick users into installing malware. Activity was concentrated in the U.S., with additional infections observed in Israel, Spain, Germany, India, and Ireland, affecting sectors including healthcare, construction, and manufacturing.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcekaspersky.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.