ConvertyFile is a browser hijacker delivered through online advertisements. In the observed campaign, ads on govsalaries[.]com associated with Red Root LTD redirected users to convertyfileapp[.]com, which delivered the installer convertyfile.exe from lukgio[.]com/condl. The analyzed sample had SHA-256 3d82200083a86df09c3b16c9095b844738a76863b1b01092b6c4dbef3b974b12 and was reportedly written in Go.
The installer presented itself as a converter utility and used installation views similar to ConvertMaster, including full-screen behavior that obscured browser activity in the background. After installation it created a desktop shortcut to the online converter site portite[.]com. During execution, ConvertyFile contacted olienti[.]com, including POST requests to /vars to retrieve dynamic configuration, /boom during execution, and /pass for apparent metrics. Returned configuration indicated Firefox was a target browser.
Its browser hijacking behavior altered search handling so that hijacked queries were first sent to scep.sqlokik[.]com, then redirected through searchdreamytab[.]com/search/, and ultimately landed on Yahoo Search. Identified campaign infrastructure included convertyfileapp[.]com, lukgio[.]com, portite[.]com, olienti[.]com, scep.sqlokik[.]com, and searchdreamytab[.]com.
The research assessed ConvertyFile is linked to ConvertMaster based on shared ad delivery patterns, similar delivery chains, common browser hijacking objectives, matching desktop-shortcut behavior, and Silent Push data showing domains in both campaigns used the same Google Ad ID, G-SS88ENC0JT.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A browser hijacker referenced as related prior research and delivered via ads, with similar installation and shortcut behavior to PDFChampions.
Browser hijacker delivered via ads that changes the browser's default search engine, with observed behavior including redirecting searches through attacker-controlled domains and creating a desktop shortcut to an online converter site.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.