logo

Threat Actors Exploit Office Assistant to Deliver Malicious Mltab Browser Plugin

ID: 0a297369-7ea3-53f8-bfb3-6d2644d7bc2c

STIX ID: report--0a297369-7ea3-53f8-bfb3-6d2644d7bc2c

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-01-06

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

QiAnXin's RedDrip Team disclosed a supply-chain malware campaign (observed since May 2024) that abuses Office Assistant v3.1.10.1 to load digitally-signed malicious components which deploy the Mltab (MadaoL Newtab) browser extension; the extension hijacks new tabs, redirects user traffic, and exfiltrates browsing and device data. The campaign has large scale impact (reporting nearly one million compromised endpoints and over 210,000 extension installations), uses multiple C2 domains and persistence mechanisms, and remains available via official add-on stores; organizations should verify Office Assistant versions, inspect/remove unauthorized extensions, and apply endpoint detection/remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.