The Comm100 Live Chat Supply Chain Attack
Updated 5 Oct 2026 · Incident date 26 Sept 2022 · vendor binary
Comm100 Live Chat desktop agent (trojanized signed installer served 27-29 September 2022); fixed in 10.0.9main.js inside the Electron app.asar archiveThe Comm100 Live Chat desktop installer, version 10.0.8, carried a JavaScript backdoor in September 2022. Comm100 later published version 10.0.9 as the clean release. The installer was signed with a valid Comm100 certificate.
CrowdStrike published the findings on 30 September 2022. The Canadian Centre for Cyber Security issued alert AL22-012 for the compromise.
What happened
Attackers placed a backdoor in a signed Comm100 installer that customers could download from the vendor site. CrowdStrike reports that the malicious installer was signed on 26 September 2022 at 14:54 UTC. It was still available on the morning of 29 September 2022.
The backdoor was a script in main.js, inside the Electron app.asar archive. It downloaded a second-stage script from api.amazonawsreplay.com. That script opened cmd.exe for a remote operator.
The operator then placed a loader, MidlrtMd.dll, next to a legitimate executable, CoreConnect.exe, so that Windows loaded the malicious DLL. The loader decrypted a file named license with a customized RC4 cipher and injected the result into notepad.exe. CrowdStrike reports targets in industrial, healthcare, technology, manufacturing, insurance, and telecommunications sectors in North America and Europe. It assesses with moderate confidence a China nexus.
The Canadian Centre for Cyber Security states that Comm100 issued a press release with remediation advice on 6 October 2022.
Affected versions
- Comm100 Live Chat 10.0.8,
Comm100LiveChat-Setup-win.exe, seen in the wild. - Comm100 Live Chat 10.0.72, which contains the same backdoor. Comm100 has not seen this file in the wild.
- 10.0.9 is the clean release published by Comm100.
The window for the download was at least 27 to 29 September 2022.
Indicators of compromise
- SHA-256 of the 10.0.8 installer:
ac5c0823d623a7999f0db345611084e0a494770c3d6dd5feeba4199deee82b86 - SHA-256 of the 10.0.72 file:
6f0fae95f5637710d1464b42ba49f9533443181262f78805d3ff13bea3b8fd45 - SHA-256 of
license:c930a28878a5dd49f7c8856473ff452ddbdab8099acd6900047d9b3c6e88edca - Domains:
api.amazonawsreplay.com,api.microsoftfileapis.com,selfhelp.windowstearns.com - URL:
api.amazonawsreplay.com/livehelp/collectandapi.amazonawsreplay.com/collect_log - IP address:
8.219.167.156(resolved for api.microsoftfileapis.com) - Files:
MidlrtMd.dllandCoreConnect.exein an unexpected folder - RC4 key in the loader:
U9ELetx8eMR8pd5koFamoOyuf9tTRTPG - Signing certificate thumbprint:
d65cdc6b3a6738951f59d4ec8cc7d42f330c6d59. The certificate is genuine, so the signature alone does not prove the file is safe.
How to check
Hash your saved installer and compare the result with the list above. On Windows, run this in PowerShell:
Get-FileHash .\Comm100LiveChat-Setup-win.exe -Algorithm SHA256
Search DNS and proxy logs for the listed domains, and look for the loader file.
Get-ChildItem C:\ -Recurse -Filter MidlrtMd.dll -ErrorAction SilentlyContinue
What to do now
- Find and isolate every system that ran version 10.0.8 or 10.0.72.
- Update to version 10.0.9 or later. The Canadian Centre for Cyber Security advises more than removing or updating the product, so plan a full investigation of the host.
- Block the listed domains and the IP address, and search logs for contact with them.
- Reset credentials used on affected systems.
- Report incidents in Canada through My Cyber Portal or contact@cyber.gc.ca.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 30 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED main.js It now downloads from the internet and restarts itself after a reboot. It did not before.
Frequently asked questions
Which Comm100 Live Chat versions contained the backdoor?
Version 10.0.8 was seen in the wild. Version 10.0.72 contains the same backdoor but Comm100 has not seen it in the wild. Version 10.0.9 is the clean release.
Was the trojanized Comm100 installer signed?
Yes. CrowdStrike reports that it was signed with a valid Comm100 certificate on 26 September 2022, so the signature does not prove the file is safe.
How do I check for the Comm100 backdoor?
Compute the SHA-256 hash of your installer and compare it with the hashes in the CrowdStrike report, and search logs for api.amazonawsreplay.com.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.