AppSuite is a browser hijacker associated in the provided content with browser-manipulation activity observed in the context of TamperedChef/BaoLoader-related investigations. The malware is described as directly modifying browser preference stores, including Firefox prefs.js and Chrome Preferences and Secure Preferences, to hijack browser behavior. The content states that Chrome Secure Preferences integrity protections can be bypassed because the HMAC key is derived from system information rather than being truly secret. AppSuite reportedly includes a dedicated native library, UtilityAddon.node, used to obtain system values needed for this browser manipulation; the presence of this DLL/native module and related API calls is highlighted as an analysis indicator of a browser hijacker. The provided material does not attribute additional capabilities, infection vectors, or specific industries targeted to AppSuite beyond browser hijacking and preference tampering, and no specific IOCs other than the UtilityAddon.node component are directly given for AppSuite.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
A new wave of malware disguised as everyday productivity tools has been quietly spreading across the internet... attackers have packaged malware inside tools like PDF editors, calendar apps, ZIP extractors, and GIF image makers. These apps work as advertised, which is exactly why victims rarely suspect anything at all.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Browser-hijacker/adware family that manipulates Chromium/Chrome settings by deriving the non-secret HMAC key used to validate Chrome 'Secure Preferences' entries, enabling persistent preference tampering without being reverted on restart.
AppSuite is a browser hijacker that manipulates browser preference files (such as Chrome's Secure Preferences and Firefox's prefs.js) to change browser settings, such as the default search engine or homepage. It uses a native library to extract system-specific values needed to bypass Chrome's Secure Preferences HMAC protection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.