← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Tracking TamperedChef Clusters via Certificate and Code Reuse
The TamperedChef malware, also known as EvilAI, represents a significant cyber threat primarily characterized by its distribution through trojanized productivity applications such as PDF editors and calendars. These applications often lead users to malicious payloads via ads, targeting users unaware of the underlying risks. Notably, this malware type demonstrates similarities with potentially unwanted programs (PUPs) and adware, incorporating robust mechanisms for persistence and utilizing deceptive end-user licensing agreements. However, its stealthiness is a notable differentiator, often remaining dormant for extended periods before executing its malicious components.
MITRE ATT&CK & Malware Families
Indicators of Compromise (5)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| CVE | CVE-2026-1731 | — | 2026-05-21 | |
| FileHash-SHA256 | 2231bfa7c7bd4a8ff12568074f83de8e4ec95c226230cccc6616a1a4416de268 | — | 2026-05-21 | |
| FileHash-SHA256 | 248de1470771904462c91f146074e49b3d7416844ec143ade53f4ac0487fdb44 | — | 2026-05-21 | |
| domain | onezipapp.com | — | 2026-05-21 | |
| hostname | www.crystalpdf.com | — | 2026-05-21 |