Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
A scheduled task named OneBUpdate or OBUpdate that launches an executable from the same installation
A scheduled task named OneBUpdate or OBUpdate that launches an executable from the same installation
One of the most consistent and revealing artifacts was the scheduled task named “OBUpdate”. This task acted as the primary persistence method for OneBrowser components.
Yet during analysis, multiple entries appeared within: HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\<Thumbprint>\Blob The Blob value, which holds the binary representation of the certificate, had been modified from its expected state, likely the injection of an unknown, unauthorized certificate.
A scheduled task named OneBUpdate or OBUpdate that launches an executable from the same installation
The installer created extensive entries within the user-level Uninstall registry keys ( HKCU\...\Uninstall\PDF_Spark_is1 ), mimicking standard software installation metadata: False Publisher and Versioning: The entries were filled with legitimate-looking details, such as the DisplayVersion (1.0.0.0) and attributing the Publisher to Mainstay Crypto LLC.
Yet during analysis, multiple entries appeared within: HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\<Thumbprint>\Blob The Blob value, which holds the binary representation of the certificate, had been modified from its expected state, likely the injection of an unknown, unauthorized certificate.
One of the most significant discoveries was its manipulation of Windows’ Trusted Root Certification Authorities... Yet during analysis, multiple entries appeared within: HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\<Thumbprint>\Blob ... likely the injection of an unknown, unauthorized certificate.
Communication relied on frequent HTTP(S) POST and GET requests, primarily directed at two domains: oneinternetbrowser[.]com/service/update2 crowdsourcesoftware[.]com
The malware made direct connections to Amazon Web Services (AWS) S3 buckets ( pdfsparkcomponent[.]s3[.]us-east-2[.]amazonaws[.]com and pdfsparkcomponents[.]s3[.]us-east-2[.]amazonaws[.]com ). This use of trusted cloud infrastructure is a modern evasion tactic... and provides an effective, high-bandwidth channel for payload retrieval.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Potentially unwanted Chromium-based browser associated with the OneBUpdate updater/persistence component. It may arrive without clear consent, persist via services or scheduled tasks, restore files after partial removal, and appear alongside other unwanted software.
Adversary-controlled browser installed as a second-stage payload to control user browsing, ads, cookies, and credentials.
A malware family distributed via fake PDF utility and browser installers that uses Inno Setup packaging, scheduled-task persistence via OBUpdate, possible DLL side-loading/repackaging, root certificate store abuse, selective self-cleanup, and HTTP(S)-based communications to operational endpoints and AWS S3 for updates or payload retrieval.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.