Threat Intelligence, AI/ML

Office Assistant abuse facilitates widespread distribution of illicit browser plugin in China

Header graphic features a laptop with a red warning triangle and alert icons, dark background with streaming green code. It suggests concepts of cybersecurity threats, hacking, and system errors.

Almost 1 million endpoints across China have been compromised with the user traffic-hijacking and information-stealing Mltab browser plugin, also known as MadaoL Newtab, as part of an attack campaign that has been exploiting the popular AI-based productivity software Office Assistant since May 2024, GBHackers News reports.

Malignant downloader logic integrated into Office Assistant version 3.1.10.1 enabled anti-analysis checks and command-and-control server communications before retrieving a manipulated OfficeTeamAddin.dll, which downloads the installer component that then ensures persistence and prompts the eventual launch of the Mltab browser extension, according to an analysis from the RedDrip Team of QiAnXin Technology's Threat Intelligence Center.

Multiple web browsers, including Google Chrome, Microsoft Edge, and QQ Browser, have been targeted by Mltab, which not only takes over targeted URLs but also redirects users to promotional hijack links. Immediate checking of installed Office Assistant versions has been recommended.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds