Blog de Zscaler
Reciba en su bandeja de entrada las últimas actualizaciones del blog de Zscaler
Intelligence Insights: October 2025
Tampered Chef serves up a smorgasbord of suspicious activity in this month’s edition of Intelligence Insights
Highlights from September
Debuting at number 1 on our top 10 most prevalent threat list is Tampered Chef, an Electron Node.JS-based threat designed to process steganographic content with arbitrary JavaScript code delivered alongside recipe or calendar-themed lures. We first saw this activity in June 2025, and initially tracked it as a potentially unwanted program (PUP) until our own research and that of other researchers uncovered the application’s suspicious and deceptive qualities. You can read more about Tampered Chef below.
Akira, an opportunistic ransomware group that steals sensitive data and operates a TOR leak site, made the list for the first time sharing spot 8 in a tie. This is the first time we’ve seen a ransomware group in our monthly top 10 list since November 2021.
Latrodectus, a downloader used by adversaries to execute arbitrary commands and deliver additional payloads, made the list this month in a tie for 8th. This is Latrodectus’s second time in the top 10 after its debut on the list in May 2025; it continues to be one of the payloads of choice for ongoing paste-and-run campaigns.
Our final newcomer to the top 10 this month is Rhadamanthys, a stealer written in C++ that is used to steal credentials, cryptocurrency wallets, and browser data, as well as download and execute additional payloads. Rhadamanthys isn’t a new threat—it first appeared in 2022 and Red Canary has been tracking it since that time—but this is the first time it’s made the list. Like Latrodectus, it’s on the list this month as a paste-and-run payload.

This month’s top 10 threats
To track pervasiveness over time, we identify the number of unique customer environments in which we observed a given threat and compare it to what we’ve seen in previous months.
Here’s how the numbers shook out for September 2025:
| Month's rank | Threat name | Threat description |
|---|---|---|
⬆ 1 | Tampered Chef | Electron Node.JS-based threat designed to process steganographic content with arbitrary JavaScript code delivered alongside recipes for meals |
⬇ 2 | Traffic distribution system, first observed in 2024, that uses compromised WordPress sites to deploy malicious code that may lead to malware families such as Rhysida and Interlock ransomware, D3F@ck Loader, Mocha Manakin, Mintsloader, and WARMCOOKIE | |
⬇ 3 | Red Canary's name for a cluster of activity, delivered via installers masquerading as legitimate free software, that progresses through several stages to a PyInstaller EXE with stealer capabilities | |
⬆ 4 | Legitimate remote access tool (RAT) that can be used as a trojan by adversaries to remotely control victim endpoints for unauthorized access | |
⬇ 5 | A loader designed to maintain persistence and deliver additional threats | |
⬆ 6* | Open-source tool that dumps credentials using various techniques | |
⬇ 6* | Activity cluster that uses a distribution scheme similar to SocGholish and uses JScript files to drop NetSupport Manager onto victim systems | |
⬆8* | Opportunistic ransomware group operating since March 2023 that steals sensitive data and operates a TOR leak site | |
⬆8* | Downloader used by adversaries to execute arbitrary commands and deliver additional payloads | |
⬇10* | Information stealer designed to target data within web browsers and locally stored files on macOS systems, with the goal of accessing sensitive information including credentials, payment card data, keychain details, and cryptocurrency wallets | |
⬆10* | Malware family used as part of a botnet. Some variants are worms and frequently spread via infected USB drives | |
⬆ 10* | Rhadamanthys | Information stealer written in C++ that is used to steal credentials, cryptocurrency wallets, and browser data, as well as download and execute additional payloads |
⬆ 10* | Dropper/Downloader that uses compromised WordPress sites to redirect users to adversary infrastructure posing as necessary browser updates to trick users into running malicious code |
⬆ = trending up from previous month ⬇= trending down from previous month ➡ = no change in rank from previous month
*Denotes a tie
Tampered Chef savors steganography
We first saw Tampered Chef in early June 2025, as a sudden high-volume wave of activity that we initially classified as a PUP before we took a closer look at its code. We weren’t the only ones doing so; within days of our first seeing it, other researchers published their findings on this threat. Tampered Chef has several suspicious and intentionally deceptive qualities that led us to reassess it as malware. Our updated classification makes it eligible for inclusion in our top 10 list, since we do not typically include adware.
The recipe-themed version of the lure disguises itself as a calorie-counting recipe tool, presented to users via sidebar or banner ads, sometimes on websites with articles that promote the tool.

Image from https://blog.dingusxmcgee.com/blog/2025/06/06/Recipe-For-Adware.html
Interacting with the ad leads to downloading the file Recipe Lister, an archive that unzips to deliver several other resources including the malicious Node.JS Electron application Recipe Finder - Recipe Lister, dynamic link libraries (DLLs), and additional hidden files. Once installed, the app reaches out to suspicious IP addresses, likely to establish command and control (C2) connections.
Tampered Chef’s other suspicious qualities include:
- Steganographic hidden command and control messages, specifically JSON messages that, in addition to containing recipes for meals, include steganographic content in the form of “invisible characters” that are removed, decoded, and executed by Tampered Chef
- File time creation changes, indicative of potential timestomping
- Anti-analysis techniques, including sandbox detection
- The ability to redirect user browser traffic and adjust browser settings

An example that shows the characters included in the JSON message
We are also tracking a similar campaign first observed in September 2025 using a calendar-themed lure—calendaromatic.exe—as described in this blog. In September 2025 we saw both Recipe Lister and Calendaromatic campaign activity. At this time, we’ve decided to track both types of lures under the umbrella of Tampered Chef. As of the end of September 2025, there has been no observed follow-on activity, additional payloads, or command execution. It could be that this threat is indeed adware, or potentially that access has not yet been operationalized.
The Great Trojan Bakeoff : Tampered Chef vs. JustAskJacky vs. Browser Assistant
Tampered Chef is not the only high-volume trojan horse application that we (and others) have observed recently. Another example is JustAskJacky, a family of NodeJS applications that masquerade as a helpful AI or utility tool while conducting reconnaissance and executing arbitrary commands in memory in the background. Another threat we’ve seen mentioned at the same time is Baoloader, which we track as Browser Assistant here at Red Canary. We are currently tracking these three threats as separate and distinct clusters, due to differences in behavior.
Here’s a very brief breakdown of how we’re differentiating them:
| Tampered Chef | JustAskJacky | Browser Assistant | |
|---|---|---|---|
: Also known as: | Calendaromatic, Recipe Lister | GoAskBobby, AskBettyHow, OpenMyManual, and many more | Baoloader |
: Masquerades as: | Recipe applications or calendar helpers | Helpful AI or utility tool, sometimes PDF-themed NodeJS application | Helpful browser extensions and, more recently, PDF readers |
: Language/file: | Node.JS Electron application | Family of NodeJS applications | JavaScript |
: Behavior: | Uses steganography for command and control messages | Typically has GUID values in its filenames, for example | May use EXE or MSI files for installation, for example |
2025 Midyear Threat Detection Report
¿Este post ha sido útil?
Exención de responsabilidad: Este blog post ha sido creado por Zscaler con fines informativos exclusivamente y se ofrece "como es" sin ninguna garantía de precisión, integridad o fiabilidad. Zscaler no asume ninguna responsabilidad por errores u omisiones ni por las acciones que se tomen basándose en la información proporcionada. Cualquier sitio web o recurso de terceros enlazado en esta publicación de blog se proporciona únicamente por conveniencia, y Zscaler no se hace responsable de su contenido ni de sus prácticas. Todo el contenido está sujeto a cambios sin previo aviso. Al acceder a este blog, acepta estos términos y reconoce ser el único responsable de verificar y utilizar la información de manera adecuada según sus necesidades.
Reciba en su bandeja de entrada las últimas actualizaciones del blog de Zscaler
Al enviar el formulario, acepta nuestra política de privacidad.
