A nasty malware called TamperedChef is hidden in a fake PDF editor app that hackers have created. At first it appears to be a legitimate tool for editing PDFs, but then it collects your passwords and most sensitive data. How unsettling, right? I'll give you the run down in simple terms. How do hackers trick people?
The sneaky part is that when you install it, nothing bad happens right away. The malware sits there quietly for about 56 days. After 56 days, by then, people have forgotten that they installed it. After its sleep, the malware goes to work!
• They advertised it using Google Ads.
• The malware sits and waits for 56 days before it attacks.
• Then it harvests passwords and leaves a backdoor.
• It appears safe, but it is a very real threat.
Fake Ads on Google
They created fake websites that offer a free application named AppSuite PDF Editor. They placed ads in Google to disguise the application as authentic and safe for computer users. If you were to see this site, you might say, "Oh neat, a free PDF editor." That is the exact reaction they want from you.Looks Authentic but Isn't
The application has all the hallmarks of a normal application once it is installed. In fact, it has even displayed certificates that include bogus company names like ECHO Infini SDN BHD. It even appears to be legitimate, but it's just bait.The Sneaky Delay
Malware Hibernates for 56 DaysThe sneaky part is that when you install it, nothing bad happens right away. The malware sits there quietly for about 56 days. After 56 days, by then, people have forgotten that they installed it. After its sleep, the malware goes to work!
What TamperedChef does
When it wakes up, TamperedChef does a lot of different bad things:- Steals passwords saved in the browser.
- Kills browser processes so it can capture locked data.
- Checks for anti-virus software and avoids it.
- Open a backdoor for hackers to install malware again.
Why This Is Important
Just consider how often you've downloaded a free tool without knowing the source, I have too! That is why this is frightening, it's something as simple as a PDF editor, and it could be a serious threat.Quick Summary
• Hackers built a fake PDF editor App.• They advertised it using Google Ads.
• The malware sits and waits for 56 days before it attacks.
• Then it harvests passwords and leaves a backdoor.
• It appears safe, but it is a very real threat.