Threat Actors Exploit Office Assistant to Deliver Malicious Mltab Browser Plugin
A malware campaign has been identified exploiting Office Assistant, a widely-used AI productivity tool in China, to distribute a browser plugin that redirects user traffic and extracts sensitive data.
A malware campaign has been identified exploiting Office Assistant, a widely-used AI productivity tool in China, to distribute a browser plugin that redirects user traffic and extracts sensitive data.
The RedDrip Team at QiAnXin Technology's Threat Intelligence Center discovered the campaign, active since at least May 2024, affecting nearly one million endpoints in China over 18 months.
The attack leverages Office Assistant's infrastructure to load malicious components that deliver the Mltab browser plugin. This plugin collects user data and redirects traffic to attacker-controlled domains. The extension has been installed over 210,000 times and remains available on the Microsoft Edge Add-ons Store.
Researchers identified the infection vector in Office Assistant version 3.1.10.1, released on Tue, May 28, 2024. The malicious downloader logic is embedded in OfficeAid.Main.exe, absent from the previous version 3.1.9.9.
The component performs anti-analysis checks and contacts the command-and-control server at ofsd.fh67k.com. The attack chain involves multiple stages of payload delivery. The initial dropper downloads OfficeTeamAddin.dll, which loads OfficeTeam.Installer.dll. This component creates a persistence mechanism using a mutex and connects to ofsg.fh67k.com for the second-stage payload.
The attack leverages Office Assistant's infrastructure to load malicious components that deliver the Mltab browser plugin.
The final payload, logkit.dll, deploys the Mltab browser plugin by executing the logkit_report export function. It identifies installed browsers, collects device information, encrypts it, and transmits it to the C2 server at of2sg.fh67k.com. The malware targets multiple browsers, including Microsoft Edge, Google Chrome, QQ Browser, Sogou Browser, Lenovo Browser, and 2345 Browser.
The Mltab plugin, labeled "MadaoL Newtab," hijacks the browser's new tab page and performs traffic redirection. The background.js script generates user identifiers and uploads browsing activity to api.g6ht.com. The plugin fetches rule configuration files from C2 servers to hijack targeted URLs.
The extension adds a deceptive context menu item labeled "Search with Baidu" that redirects users to promotional links. The myload.js and new_tab_page.js components inject tracking scripts and fetch replacement rules to replace legitimate links with redirect URLs.
Command and Control servers associated with this campaign are listed among the top one million domains on OpenDNS, aiding in evasion of blocklists. QiAnXin's Tianqing endpoint protection can detect and remove Mltab-related components. Organizations using QiAnXin's threat intelligence products have access to detection capabilities for this threat.
Users of Office Assistant in China should verify their installed version and check for unauthorized browser extensions related to Mltab or MadaoL Newtab.
Based on reporting by GBHackers.
