logo

Popular Chinese Utility Hijacked to Deploy Browser Malware

ID: f6d680ef-9387-5693-aa19-8b92a95390cf

STIX ID: report--f6d680ef-9387-5693-aa19-8b92a95390cf

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-01-07

Date Updated: 2026-04-22

Author: Ddos

...
...

QiAnXin’s RedDrip Team uncovered a supply-chain malware campaign in the widely used Office Assistant tool: version 3.1.10.1 added downloader logic that fetched a DLL (OfficeTeamAddin.dll) signed with third-party certificates and deployed the Mltab browser-hijacker (installed >210,000 times), which collects user data, hijacks new-tab/search behavior, and redirects links for monetization; the campaign leverages C2 domains (e.g., fh67k.com, eybyyffs.com, cjtab.com), uses revoked certificates and persistence/evasion techniques, and reportedly affected nearly one million endpoints, with QiAnXin updating detections and urging users to scan and remove suspicious extensions such as "MadaoL Newtab".

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.