Researchers reported that the TamperedChef malware operation, also tracked as EvilAI, has distributed trojanized productivity software through malvertising and polished download sites, posing as tools including Calendaromatic, DocuFlex, AppSuite PDF, OneZip, CrystalPDF, PDF-Ezy, and RapiDoc. The campaign has been active since early 2023 and uses valid code-signing certificates, delayed second-stage delivery, persistence mechanisms, and stealthy execution to evade detection while deploying adware, browser hijackers, information stealers, RATs, and proxy-style payloads. Unit 42 said it identified more than 4,000 unique samples and 100+ variants, with infections observed in more than half of monitored enterprise environments.
Analysis of the rapidoc subcluster linked the activity to broader fake-app campaigns and highlighted code reuse, certificate rotation, and infrastructure overlap with related BaoLoader activity. Researchers described two main branches: a Calendaromatic 7zSFX dropper line tied to shell companies including CROWN SKY LLC and MARKET FUSION INNOVATIONS LLC, and a Neutralinojs-based RapiDoc stage-0 line tied to CANDY TECH LTD. A recurring tracking artifact was the GlobalSign GCC R45 EV CodeSigning CA 2020 sub-CA certificate with serial 77BD0E05B7590BB61D4761531E3F75ED, which was used to connect shell-company activity across Israel, Ukraine, Panama, Malaysia, Estonia, and the United States; researchers also found an unsigned sibling sample communicating with calendaromatic.com, suggesting some operators may be dropping code signing to reduce attribution risk.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Unit 42 disclosed that TamperedChef comprised more than 4,000 unique samples and over 100 variants, with detections in more than half of monitored enterprise environments worldwide. The researchers also described three activity clusters and said the malware delivered payloads including stealers, RATs, adware, browser hijackers, and proxy-style tools.
Analysis uncovered a novel unsigned sibling sample communicating with calendaromatic.com, suggesting some operators may be moving away from code signing to make tracking harder. The finding added to evidence of infrastructure and code reuse across related TamperedChef and BaoLoader activity.
Researchers identified a separate 'rapidoc' subcluster built around a Neutralinojs-based RapiDoc stage-0 loader and linked it to CANDY TECH LTD. The branch was associated with signed binaries, persistence, delayed activation, and second-stage payload delivery.
One identified TamperedChef branch used Calendaromatic-themed 7zSFX droppers and was tied to code-signing activity associated with shell companies including CROWN SKY LLC and MARKET FUSION INNOVATIONS LLC. This branch helped establish certificate and code-reuse links across the broader malware cluster.
Researchers said the TamperedChef/EvilAI operation has been active since early 2023, distributing malware disguised as productivity software such as PDF editors, calendar apps, ZIP tools, and similar utilities. The campaign used professional download sites and delayed second-stage delivery to reduce suspicion and evade detection.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
6 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourceorigin-unit42.paloaltonetworks.com
Open sourcegist.github.com
Open sourcelabs.withsecure.com
Open sourcegbhackers.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.