Hacker at laptop displaying warning icon surrounded by hexagonal shields, locks, malware, and threat labels

Daily Dose of Cybersecurity News - August 31, 2025

TamperedChef Infostealer Distributed via Fraudulent PDF Editor

High

What happened

Threat actors utilized multiple websites, promoted through Google ads, to distribute a deceptive PDF editing application named AppSuite PDF Editor, which installs the TamperedChef information-stealing malware on users' systems.

Who is affected

Individuals and organizations downloading the fraudulent AppSuite PDF Editor are at risk of malware infection and data theft.

Why it matters

The campaign's sophistication, including the use of over 50 domains and fraudulent certificates from multiple companies, highlights the evolving tactics of cybercriminals. The delayed activation of malicious components increases the challenge of detection, posing significant risks to data security.

How it could have been prevented

- Avoid downloading software from unverified sources. - Be cautious of software promoted through online ads. - Regularly update and run reputable antivirus and anti-malware programs.

Relevant professional terms

Infostealer
A type of malware designed to gather sensitive information from an infected system, such as login credentials and personal data.
Residential Proxy
A proxy server that uses an IP address provided by an Internet Service Provider (ISP) to appear as a regular user, often used to mask malicious activities.

Recommended reading: BleepingComputer

Attackers Exploit Velociraptor Forensic Tool to Deploy Visual Studio Code for C2 Tunneling

High

What happened

Threat actors utilized the open-source forensic tool Velociraptor to download and execute Visual Studio Code, aiming to establish a tunnel to a command-and-control (C2) server.

Who is affected

Organizations using Velociraptor and Visual Studio Code are potential targets of this attack vector.

Why it matters

This incident highlights the evolving tactics of attackers who repurpose legitimate tools for malicious purposes, complicating detection and response efforts.

How it could have been prevented

Implementing endpoint detection and response systems, monitoring for unauthorized use of forensic tools, and adhering to best practices for system security and backups.

Relevant professional terms

Living-off-the-land (LotL) techniques
Methods where attackers use legitimate system tools for malicious purposes to evade detection.
Command-and-control (C2) server
A server used by attackers to maintain communications with compromised systems within a target network.

Recommended reading: Sophos Reports on Attackers Abusing Velociraptor for Malicious Purposes