Threat actors used Google Ads malvertising and look-alike websites to distribute a trojanized Windows application branded as AppSuite PDF Editor, delivering an information-stealing payload tracked as TamperedChef. Sophos X-Ops/MDR investigations reported the operation was first detected in September 2025, with infrastructure activity traced back to late June 2025, when attackers registered multiple spoofed sites to impersonate legitimate PDF-editing and “manual finder” tooling. The campaign exploited common search behavior—particularly users looking for PDF editors and appliance/product manuals—to drive victims to malicious installers that appeared legitimate but silently deployed an infostealer targeting browser-stored data and other sensitive information.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
On publication of the research, Sophos warned that anyone who installed “AppSuite PDF Editor” should assume browser credentials were compromised. The company advised defenders to hunt for the application and review browser download alerts for suspicious activity.
Sophos X-Ops reported that the campaign used valid code-signing certificates, including EV certificates, from Malaysian and US-registered entities to make the malware appear trustworthy and help bypass Windows SmartScreen. The disclosure highlighted the campaign’s use of trusted signing to improve infection success.
Victimology analysis showed the campaign reached at least 19 countries, with higher observed concentrations in Germany, the UK, and France. Sophos noted the geographic pattern may reflect incidental exposure rather than deliberate targeting.
Sophos first identified the campaign in September 2025 during managed detection and response investigations. By that point, the operation had already affected more than 100 customer systems.
After a long delay intended to evade detection, the infostealer component began executing to harvest browser-stored passwords, cookies, and autofill data from victims. Researchers said the delay was about 56 days, matching the lifecycle of typical ad campaigns.
Attackers started using Google Ads and search-result infiltration to lure Windows users to malicious sites hosting a trojanized MSI installer for “AppSuite PDF Editor.” The installer appeared legitimate but was designed to deploy the TamperedChef infostealer through a multi-stage infection chain.
The malvertising operation began when threat actors registered look-alike websites advertising a trojanized Windows application called “AppSuite PDF Editor.” The campaign also used “Manual FinderApp” branding in malware metadata to target users searching for product manuals.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.