Almost 1 million endpoints across China have been compromised with the user traffic-hijacking and information-stealing Mltab browser plugin, also known as MadaoL Newtab, as part of an attack campaign that has been exploiting the popular AI-based productivity software Office Assistant since May 2024, GBHackers News reports.Malignant downloader logic integrated into Office Assistant version 3.1.10.1 enabled anti-analysis checks and command-and-control server communications before retrieving a manipulated OfficeTeamAddin.dll, which downloads the installer component that then ensures persistence and prompts the eventual launch of the Mltab browser extension, according to an analysis from the RedDrip Team of QiAnXin Technology's Threat Intelligence Center.Multiple web browsers, including Google Chrome, Microsoft Edge, and QQ Browser, have been targeted by Mltab, which not only takes over targeted URLs but also redirects users to promotional hijack links. Immediate checking of installed Office Assistant versions has been recommended.
Threat Intelligence, AI/ML
Office Assistant abuse facilitates widespread distribution of illicit browser plugin in China
(Adobe Stock)
An In-Depth Guide to AI
Get essential knowledge and practical strategies to use AI to better your security program.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
