Trojanized installers of widely known software have been leveraged to spread a JavaScript backdoor and achieve persistence as part of the ongoing global malvertising campaign TamperedChef, reports The Hacker News.Attackers have poisoned Bing search results for PDF editors and product manuals with links redirecting to NameCheap-registered domains that lure users into downloading the fake installers, according to an Acronis Threat Research Unit analysis. Agreeing to the licensing terms upon execution of the installer triggers a thank you message in a new browser tab, as an XML file creating a scheduled task for JavaScript malware delivery is covertly installed. Most compromised by the backdoor were healthcare, manufacturing, and construction organizations in the U.S, Israel, Spain, Germany, India, and Ireland."These industries appear especially vulnerable to this type of campaign, likely due to their reliance on highly specialized and technical equipment, which often prompts users to search online for product manuals one of the behaviors exploited by the TamperedChef campaign," said Acronis researchers.
