ConvertMaster is a browser hijacker associated with ad-delivered campaigns that masquerade as converter utilities. The provided content directly links later families, including ConvertyFile and PDFChampions, to ConvertMaster based on shared ad delivery patterns, similar delivery chains, the objective of hijacking browser search settings, and the distinctive behavior of creating a desktop shortcut that opens an online converter site. The campaigns were observed being delivered via online advertisements, including ads served on govsalaries[.]com. ConvertMaster is specifically noted as sharing with ConvertyFile the behavior of injecting the default search engine and creating a desktop shortcut that points to an online converter. The content also states that PDFChampions was linked by the researcher to prior browser hijackers named ConvertMaster and ConvertyFile. Silent Push data cited in the content indicated that domains associated with the ConvertMaster- and ConvertyFile-related campaigns used the same Google Ad ID, G-SS88ENC0JT. High-confidence infrastructure, hashes, or actor attribution specific to ConvertMaster itself are not provided in the content beyond these relationships and behavioral similarities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A browser hijacker referenced as related prior research and delivered via ads, with similar behavior to PDFChampions such as using a desktop link to bring the user to an online converter.
Related browser hijacker referenced as sharing similar delivery, browser search hijacking objectives, and desktop shortcut behavior with ConvertyFile.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.