The Comm100 Live Chat Supply Chain Attack

Updated 5 Oct 2026 · Incident date 26 Sept 2022 · vendor binary

PackageComm100 Live Chat desktop agent (trojanized signed installer served 27-29 September 2022); fixed in 10.0.9
Filemain.js inside the Electron app.asar archive

The Comm100 Live Chat desktop installer, version 10.0.8, carried a JavaScript backdoor in September 2022. Comm100 later published version 10.0.9 as the clean release. The installer was signed with a valid Comm100 certificate.

CrowdStrike published the findings on 30 September 2022. The Canadian Centre for Cyber Security issued alert AL22-012 for the compromise.

What happened

Attackers placed a backdoor in a signed Comm100 installer that customers could download from the vendor site. CrowdStrike reports that the malicious installer was signed on 26 September 2022 at 14:54 UTC. It was still available on the morning of 29 September 2022.

The backdoor was a script in main.js, inside the Electron app.asar archive. It downloaded a second-stage script from api.amazonawsreplay.com. That script opened cmd.exe for a remote operator.

The operator then placed a loader, MidlrtMd.dll, next to a legitimate executable, CoreConnect.exe, so that Windows loaded the malicious DLL. The loader decrypted a file named license with a customized RC4 cipher and injected the result into notepad.exe. CrowdStrike reports targets in industrial, healthcare, technology, manufacturing, insurance, and telecommunications sectors in North America and Europe. It assesses with moderate confidence a China nexus.

The Canadian Centre for Cyber Security states that Comm100 issued a press release with remediation advice on 6 October 2022.

Affected versions

The window for the download was at least 27 to 29 September 2022.

Indicators of compromise

How to check

Hash your saved installer and compare the result with the list above. On Windows, run this in PowerShell:

Get-FileHash .\Comm100LiveChat-Setup-win.exe -Algorithm SHA256

Search DNS and proxy logs for the listed domains, and look for the loader file.

Get-ChildItem C:\ -Recurse -Filter MidlrtMd.dll -ErrorAction SilentlyContinue

What to do now

  1. Find and isolate every system that ran version 10.0.8 or 10.0.72.
  2. Update to version 10.0.9 or later. The Canadian Centre for Cyber Security advises more than removing or updating the product, so plan a full investigation of the host.
  3. Block the listed domains and the IP address, and search logs for contact with them.
  4. Reset credentials used on affected systems.
  5. Report incidents in Canada through My Cyber Portal or contact@cyber.gc.ca.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Comm100-prev --new Comm100-current
files scanned: 30

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    main.js
           It now downloads from the internet and restarts itself after a reboot. It did not before.

Frequently asked questions

Which Comm100 Live Chat versions contained the backdoor?

Version 10.0.8 was seen in the wild. Version 10.0.72 contains the same backdoor but Comm100 has not seen it in the wild. Version 10.0.9 is the clean release.

Was the trojanized Comm100 installer signed?

Yes. CrowdStrike reports that it was signed with a valid Comm100 certificate on 26 September 2022, so the signature does not prove the file is safe.

How do I check for the Comm100 backdoor?

Compute the SHA-256 hash of your installer and compare it with the hashes in the CrowdStrike report, and search logs for api.amazonawsreplay.com.

Sources

  1. crowdstrike.com/en-us/blog/new-supply-chain-attack-leverages-comm100-chat-installer/
  2. cyber.gc.ca/en/alerts-advisories/supply-chain-compromise-impacting-comm100-live-chat-software
  3. socradar.io/blog/comm100-installer-abused-in-supply-chain-attack-to-distribute-malware/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free