PULSE NAME
Tracking TamperedChef Clusters via Certificate and Code Reuse
WHITE PetrP.73 2026-05-21 Modified: 2026-05-21
5
IOCs
LOW VOLUME
The TamperedChef malware, also known as EvilAI, represents a significant cyber threat primarily characterized by its distribution through trojanized productivity applications such as PDF editors and calendars. These applications often lead users to malicious payloads via ads, targeting users unaware of the underlying risks. Notably, this malware type demonstrates similarities with potentially unwanted programs (PUPs) and adware, incorporating robust mechanisms for persistence and utilizing deceptive end-user licensing agreements. However, its stealthiness is a notable differentiator, often remaining dormant for extended periods before executing its malicious components.
Indicators of Compromise (5)
All CVE FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2026-1731 2026-05-21
FileHash-SHA256 2231bfa7c7bd4a8ff12568074f83de8e4ec95c226230cccc6616a1a4416de268 2026-05-21
FileHash-SHA256 248de1470771904462c91f146074e49b3d7416844ec143ade53f4ac0487fdb44 2026-05-21
domain onezipapp.com 2026-05-21
hostname www.crystalpdf.com 2026-05-21