Zscaler Blog

Erhalten Sie die neuesten Zscaler Blog-Updates in Ihrem Posteingang

Best Practices

Intelligence Insights: October 2025

image
THE RED CANARY TEAM
Oktober 23, 2025 - 6 min read

Tampered Chef serves up a smorgasbord of suspicious activity in this month’s edition of Intelligence Insights

 

Highlights from September

Debuting at number 1 on our top 10 most prevalent threat list is Tampered Chef, an Electron Node.JS-based threat designed to process steganographic content with arbitrary JavaScript code delivered alongside recipe or calendar-themed lures. We first saw this activity in June 2025, and initially tracked it as a potentially unwanted program (PUP) until our own research and that of other researchers uncovered the application’s suspicious and deceptive qualities. You can read more about Tampered Chef below.

Akira, an opportunistic ransomware group that steals sensitive data and operates a TOR leak site, made the list for the first time sharing spot 8 in a tie. This is the first time we’ve seen a ransomware group in our monthly top 10 list since November 2021.

Latrodectus, a downloader used by adversaries to execute arbitrary commands and deliver additional payloads, made the list this month in a tie for 8th. This is Latrodectus’s second time in the top 10 after its debut on the list in May 2025; it continues to be one of the payloads of choice for ongoing paste-and-run campaigns.

Our final newcomer to the top 10 this month is Rhadamanthys, a stealer written in C++ that is used to steal credentials, cryptocurrency wallets, and browser data, as well as download and execute additional payloads. Rhadamanthys isn’t a new threat—it first appeared in 2022 and Red Canary has been tracking it since that time—but this is the first time it’s made the list. Like Latrodectus, it’s on the list this month as a paste-and-run payload.

SecOps Weekly video thumbnail

 

This month’s top 10 threats

To track pervasiveness over time, we identify the number of unique customer environments in which we observed a given threat and compare it to what we’ve seen in previous months.

Here’s how the numbers shook out for September 2025:

Month's rankThreat nameThreat description

⬆ 1

Tampered Chef

Electron Node.JS-based threat designed to process steganographic content with arbitrary JavaScript code delivered alongside recipes for meals

⬇ 2

KongTuke

Traffic distribution system, first observed in 2024, that uses compromised WordPress sites to deploy malicious code that may lead to malware families such as Rhysida and Interlock ransomware, D3F@ck Loader, Mocha Manakin, Mintsloader, and WARMCOOKIE

⬇ 3

Amber Albatross

Red Canary's name for a cluster of activity, delivered via installers masquerading as legitimate free software, that progresses through several stages to a PyInstaller EXE with stealer capabilities

⬆ 4

NetSupport Manager

Legitimate remote access tool (RAT) that can be used as a trojan by adversaries to remotely control victim endpoints for unauthorized access

⬇ 5

CleanUpLoader

A loader designed to maintain persistence and deliver additional threats

⬆ 6*

Mimikatz

Open-source tool that dumps credentials using various techniques

⬇ 6*

Scarlet Goldfinch

Activity cluster that uses a distribution scheme similar to SocGholish and uses JScript files to drop NetSupport Manager onto victim systems

⬆8*

Akira

Opportunistic ransomware group operating since March 2023 that steals sensitive data and operates a TOR leak site

⬆8*

Latrodectus

Downloader used by adversaries to execute arbitrary commands and deliver additional payloads

⬇10*

Atomic Stealer

Information stealer designed to target data within web browsers and locally stored files on macOS systems, with the goal of accessing sensitive information including credentials, payment card data, keychain details, and cryptocurrency wallets

⬆10*

Gamarue

Malware family used as part of a botnet. Some variants are worms and frequently spread via infected USB drives

⬆ 10*

Rhadamanthys

Information stealer written in C++ that is used to steal credentials, cryptocurrency wallets, and browser data, as well as download and execute additional payloads

⬆ 10*

SocGholish

Dropper/Downloader that uses compromised WordPress sites to redirect users to adversary infrastructure posing as necessary browser updates to trick users into running malicious code

⬆ = trending up from previous month ⬇= trending down from previous month ➡ = no change in rank from previous month

*Denotes a tie

Tampered Chef savors steganography

We first saw Tampered Chef in early June 2025, as a sudden high-volume wave of activity that we initially classified as a PUP before we took a closer look at its code. We weren’t the only ones doing so; within days of our first seeing it, other researchers published their findings on this threat. Tampered Chef has several suspicious and intentionally deceptive qualities that led us to reassess it as malware. Our updated classification makes it eligible for inclusion in our top 10 list, since we do not typically include adware.

The recipe-themed version of the lure disguises itself as a calorie-counting recipe tool, presented to users via sidebar or banner ads, sometimes on websites with articles that promote the tool.

Image

Image from https://blog.dingusxmcgee.com/blog/2025/06/06/Recipe-For-Adware.html

Interacting with the ad leads to downloading the file Recipe Lister, an archive that unzips to deliver several other resources including the malicious Node.JS Electron application Recipe Finder - Recipe Lister, dynamic link libraries (DLLs), and additional hidden files. Once installed, the app reaches out to suspicious IP addresses, likely to establish command and control (C2) connections.

Tampered Chef’s other suspicious qualities include:

  • Steganographic hidden command and control messages, specifically JSON messages that, in addition to containing recipes for meals, include steganographic content in the form of “invisible characters” that are removed, decoded, and executed by Tampered Chef
  • File time creation changes, indicative of potential timestomping
  • Anti-analysis techniques, including sandbox detection
  • The ability to redirect user browser traffic and adjust browser settings

 

Image

An example that shows the characters included in the JSON message

We are also tracking a similar campaign first observed in September 2025 using a calendar-themed lure—calendaromatic.exe—as described in this blog. In September 2025 we saw both Recipe Lister and Calendaromatic campaign activity. At this time, we’ve decided to track both types of lures under the umbrella of Tampered Chef. As of the end of September 2025, there has been no observed follow-on activity, additional payloads, or command execution. It could be that this threat is indeed adware, or potentially that access has not yet been operationalized.

 

The Great Trojan Bakeoff : Tampered Chef vs. JustAskJacky vs. Browser Assistant

Tampered Chef is not the only high-volume trojan horse application that we (and others) have observed recently. Another example is JustAskJacky, a family of NodeJS applications that masquerade as a helpful AI or utility tool while conducting reconnaissance and executing arbitrary commands in memory in the background. Another threat we’ve seen mentioned at the same time is Baoloader, which we track as Browser Assistant here at Red Canary. We are currently tracking these three threats as separate and distinct clusters, due to differences in behavior.

Here’s a very brief breakdown of how we’re differentiating them:

 Tampered ChefJustAskJackyBrowser Assistant

:

Also known as:

Calendaromatic, Recipe Lister

GoAskBobby, AskBettyHow, OpenMyManual, and many more

Baoloader

:

Masquerades as:

Recipe applications or calendar helpers

Helpful AI or utility tool, sometimes PDF-themed NodeJS application

Helpful browser extensions and, more recently, PDF readers

:

Language/file:

Node.JS Electron application

Family of NodeJS applications

JavaScript

:

Behavior:

Uses steganography for command and control messages

Typically has GUID values in its filenames, for example 24c92c24-5c4e-451a-8885-9509dc69ab38.js, and creates a scheduled task with the above GUID JS filename for persistence

May use EXE or MSI files for installation, for example PDF Editor.exe or pdfviewer.msi; adds registry keys for persistence

 

2025 Midyear Threat Detection Report

You've read about the top threats of the last month, how about for the last six months? The 2025 Midyear Threat Detection Report provides in-depth analysis and actionable guidance on every page.

form submtited
Danke fürs Lesen

War dieser Beitrag nützlich?

Haftungsausschluss: Dieser Blog-Beitrag wurde von Zscaler ausschließlich zu Informationszwecken erstellt und wird ohne jegliche Garantie für Richtigkeit, Vollständigkeit oder Zuverlässigkeit zur Verfügung gestellt. Zscaler übernimmt keine Verantwortung für etwaige Fehler oder Auslassungen oder für Handlungen, die auf der Grundlage der bereitgestellten Informationen vorgenommen werden. Alle in diesem Blog-Beitrag verlinkten Websites oder Ressourcen Dritter werden nur zu Ihrer Information zur Verfügung gestellt, und Zscaler ist nicht für deren Inhalte oder Datenschutzmaßnahmen verantwortlich. Alle Inhalte können ohne vorherige Ankündigung geändert werden. Mit dem Zugriff auf diesen Blog-Beitrag erklären Sie sich mit diesen Bedingungen einverstanden und nehmen zur Kenntnis, dass es in Ihrer Verantwortung liegt, die Informationen zu überprüfen und in einer Ihren Bedürfnissen angemessenen Weise zu nutzen.

Erhalten Sie die neuesten Zscaler Blog-Updates in Ihrem Posteingang

Mit dem Absenden des Formulars stimmen Sie unserer Datenschutzrichtlinie zu.