The official installer for the Comm100 Live Chat application, a widely used SaaS (software-as-a-service) that businesses use to communicate with customers and website visitors, has been trojanized as part of a new supply chain attack.
A report from CrowdStrike says the infected variant was available from the vendor's website from at least September 26th until the morning of September 29th.
Because the trojanized installer used a valid digital signature, antivirus solutions would not trigger warnings when it was launched, allowing a hidden supply chain attack.

Backdoor details
CrowdStrike says the attackers implanted a JavaScript backdoor in the “main.js” file present in the following versions of the Comm100 Live Chat installer:
- 10.0.72 with SHA256 Hash 6f0fae95f5637710d1464b42ba49f9533443181262f78805d3ff13bea3b8fd45
- 10.0.8 with SHA256 Hash ac5c0823d623a7999f0db345611084e0a494770c3d6dd5feeba4199deee82b86
The backdoor retrieves an obfuscated second-stage JS script from a hard-coded URL (“http[:]//api.amazonawsreplay[.]com/livehelp/collect”), which gives attackers remote shell access to “victimized endpoints” via the command line.

CrowdStrike observed post-compromise activity, such as the deployment of malicious loaders (“MidlrtMd.dll”) that use the DLL order-hijacking technique to load the payload within the context of legitimate Windows processes , such as “notepad.exe,” that execute directly from memory.
The loader takes the final payload (“license”) from the C2 and uses a hard-coded RC4 key to decrypt it.
Who carried out the attack?
Crowdstrike attributes the attack – with all reservations – to threat actors based in China and, more specifically, to a cluster previously seen targeting Asian online gambling entities.
This is based on the following characteristic techniques and findings:
- using chat software to deliver malware
- using the binary Microsoft Metadata Merge Utility to load a malicious DLL named MidlrtMd.dll
- “domain-naming convention” for command and control (C2) servers using Microsoft and Amazon-themed domains along with 'api.' subdomains
- C2 domains are hosted on Alibaba's infrastructure
- the code for the final payload contains comments in Chinese
Researchers reported the issue to Comm100, and the developer released a clean installer, version 10.0.9. Users are advised to update the Live Chat app immediately.
At present, Comm100 has not provided an explanation as to how the attackers managed to gain access to its systems and “poison” the legitimate installer.
Yesterday, the Canadian Centre for Cybersecurity published an alert about the incident to help raise awareness among organizations that may be using a trojanized version of the Comm100 Live Chat product.
In the publication, the organization emphasizes that upgrading to the latest, non-trojanized version is not enough to eliminate the risk of a breach because threat actors may have already established persistence.
For more details, see CrowdStrike's report
Information source: bleepingcomputer.com
