Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Threat Actors Exploit Office Assistant to Deliver Malicious Mltab Browser Plugin

A malware campaign has been identified exploiting Office Assistant, a widely-used AI productivity tool in China, to distribute a browser plugin that redirects user traffic and extracts sensitive data.

A malware campaign has been identified exploiting Office Assistant, a widely-used AI productivity tool in China, to distribute a browser plugin that redirects user traffic and extracts sensitive data.

The RedDrip Team at QiAnXin Technology's Threat Intelligence Center discovered the campaign, active since at least May 2024, affecting nearly one million endpoints in China over 18 months.

The attack leverages Office Assistant's infrastructure to load malicious components that deliver the Mltab browser plugin. This plugin collects user data and redirects traffic to attacker-controlled domains. The extension has been installed over 210,000 times and remains available on the Microsoft Edge Add-ons Store.

Researchers identified the infection vector in Office Assistant version 3.1.10.1, released on Tue, May 28, 2024. The malicious downloader logic is embedded in OfficeAid.Main.exe, absent from the previous version 3.1.9.9.

The component performs anti-analysis checks and contacts the command-and-control server at ofsd.fh67k.com. The attack chain involves multiple stages of payload delivery. The initial dropper downloads OfficeTeamAddin.dll, which loads OfficeTeam.Installer.dll. This component creates a persistence mechanism using a mutex and connects to ofsg.fh67k.com for the second-stage payload.

The attack leverages Office Assistant's infrastructure to load malicious components that deliver the Mltab browser plugin.
Brooke Sanders · Thehackingpost

The final payload, logkit.dll, deploys the Mltab browser plugin by executing the logkit_report export function. It identifies installed browsers, collects device information, encrypts it, and transmits it to the C2 server at of2sg.fh67k.com. The malware targets multiple browsers, including Microsoft Edge, Google Chrome, QQ Browser, Sogou Browser, Lenovo Browser, and 2345 Browser.

The Mltab plugin, labeled "MadaoL Newtab," hijacks the browser's new tab page and performs traffic redirection. The background.js script generates user identifiers and uploads browsing activity to api.g6ht.com. The plugin fetches rule configuration files from C2 servers to hijack targeted URLs.

The extension adds a deceptive context menu item labeled "Search with Baidu" that redirects users to promotional links. The myload.js and new_tab_page.js components inject tracking scripts and fetch replacement rules to replace legitimate links with redirect URLs.

Advertisement

Command and Control servers associated with this campaign are listed among the top one million domains on OpenDNS, aiding in evasion of blocklists. QiAnXin's Tianqing endpoint protection can detect and remove Mltab-related components. Organizations using QiAnXin's threat intelligence products have access to detection capabilities for this threat.

Users of Office Assistant in China should verify their installed version and check for unauthorized browser extensions related to Mltab or MadaoL Newtab.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories