EvilAI and TamperedChef represent two intertwined malware campaigns that rely on the abuse of Google Ads to target victims. Since 2025, operators behind these campaigns have distributed trojanized productivity applications—including PDF tools, recipe generators, browsers, document readers, and calendar utilities—through malvertising, SEO poisoning, and template-based modern lure websites.
Operators of these campaigns seem to have a future goal: gain persistent access to victims through malicious productivity applications, and wait for long periods of time before activating hidden malicious capabilities. These capabilities include remote access, command and control (C2), and data exfiltration.
Trinity Cyber has prevented hundreds of EvilAI and TamperedChef attacks targeting customers in 2026, giving a unique view into how these campaigns are evolving.
Our technical brief analyzes the similarities between TamperedChef and EvilAI through the lens of several campaigns Full Content InspectionTM (FCI) has recently prevented.
Both EvilAI and TamperedChef are effective because they do not behave like conventional malware. The applications perform the function advertised to the user, but they also establish persistence, collect system information, contact C2 infrastructure, and enable the download of malicious payloads for future malicious activity. Users are likely to keep the productivity tools installed, giving the operators behind these campaigns access long-term access to infected endpoints.
Peeling back the layers reveals similarities between EvilAI and TamperedChef:
.jpg?width=870&height=376&name=26-Trinity%20Cyber%20Evil%20AI%20and%20TamperedChef%20-%20Supporting%20Graphics%203%20(1).jpg)
Both malware families make extensive use of Extended Validation (EV) code-signing certificates. Installers observed in these campaigns have been signed under frequently changing corporate identities (mostly AdTech related) with limited public business history. Certificate rotation, disposable domains, branding templates, and changing executable formats allow the operators to replace infrastructure quickly when certificates are revoked, or applications are detected.
A Closer Look at TipRecipe
Trinity Cyber observed these tactics in a recent food-themed campaign involving tiprecipe[.]com. The site presented an AI-assisted recipe application through a polished landing page and distributed the installer using a cloud-hosted download location.
.jpg?width=6478&height=2800&name=26-Trinity%20Cyber%20Evil%20AI%20and%20TamperedChef%20-%20Supporting%20Graphics%204%20(1).jpg)
The initial browser request contained Google Analytics 4 (GA4) parameters, indicating that the visitor reached the lure website from ads running on legitimate third-party websites. Trinity Cyber found these ads running at large scale on several popular and legitimate websites, demonstrating that users can encounter EvilAI and TamperedChef without looking for anything malicious.
The site’s JavaScript performed several functions beyond rendering the page. It processed campaign parameters, tracked visits and downloads, filtered prospective victims, and directed qualifying users to EvilAI/TamperedChef installers. Related campaigns use similar website templates, domain names, installer naming patterns, and food-themed branding, suggesting that operators can generate and deploy new variants programmatically with limited changes to the underlying delivery infrastructure.
The downloaded installers were packaged with common deployment frameworks and signed with Extended Validation code-signing certificates. In some cases, visitors even received a legitimate WinRAR installer rather than malware. This type of selective delivery can frustrate automated analysis and produce different outcomes for researchers, scanners, and victims.
When executed, the TipRecipe sample contacted food-themed C2 domains registered by operators behind these campaigns. The installers used hardcoded C2 configurations and JSON-based check-in traffic to track victim installs. This same infrastructure is later used to access infected victims and deliver additional malware on demand.
Why Traditional Defenses Fall Short
Traditional security solutions depend heavily on reputation, endpoint signatures, or static indicators to identify threats. A newly registered domain may not yet have a negative reputation, and a valid digital signature can make an installer appear trustworthy. The application may contain enough legitimate functionality to avoid simple behavioral classification. By the time endpoint controls recognize a specific hash, certificate, or domain; the operators may already have moved to another variant.
How Full Content Inspection Changes the Outcome
Trinity Cyber’s approach targets tactics, techniques, and procedures (TTPs) rather than domains or IP addresses, catching malware like EvilAI/TamperedChef before they have a chance to infect customers.
FCI evaluates both content and behavior within network sessions and files. For example, the TipRecipe campaign was prevented at the first-stage HTTP request, before the user downloaded or executed the installer. Analysis of the web response and associated JavaScript revealed the delivery logic, tracking behavior, cloud-hosted payload location, and campaign structure – without another compromise or infected victim.
This is particularly important for campaigns that use:
- Newly registered or low-reputation domains
- Legitimate advertising platforms and benign publisher websites
- Valid code-signing certificates
- Rapidly changing hashes and filenames
- Cloud CDNs and common application frameworks
- Functional decoy software that delays malicious behavior
Key Takeaways
- Trust signals are no longer sufficient. Valid certificates, professional websites, legitimate advertising platforms, and functional software can all be incorporated into a malicious delivery chain.
- EvilAI and TamperedChef are dynamic and rapidly evolving. Reusable templates, rotating certificates, disposable domains, and dynamically branded installers allow operators to rebuild faster than legacy defenses can adapt.
- Upstream prevention reduces the need for endpoint detection. FCI stopped the TipRecipe campaign at the initial web request, before digitally signed malware reached the endpoint or established persistence.
As attackers continue to exploit trusted delivery chains, organizations need security that prevents malicious content before they reach another victim.
Learn how Trinity Cyber’s Platform makes that possible.
