Popular Chinese Utility Hijacked to Deploy Browser Malware
ID: f6d680ef-9387-5693-aa19-8b92a95390cf
STIX ID: report--f6d680ef-9387-5693-aa19-8b92a95390cf
Feed Name: securityonline.info
QiAnXin’s RedDrip Team uncovered a supply-chain malware campaign in the widely used Office Assistant tool: version 3.1.10.1 added downloader logic that fetched a DLL (OfficeTeamAddin.dll) signed with third-party certificates and deployed the Mltab browser-hijacker (installed >210,000 times), which collects user data, hijacks new-tab/search behavior, and redirects links for monetization; the campaign leverages C2 domains (e.g., fh67k.com, eybyyffs.com, cjtab.com), uses revoked certificates and persistence/evasion techniques, and reportedly affected nearly one million endpoints, with QiAnXin updating detections and urging users to scan and remove suspicious extensions such as "MadaoL Newtab".
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
