FILEMembers
FILE

2345Pinyin IME Runs Six-Year Covert Delivery Pipeline Behind Ad-Injection Cover

The 2345Pinyin Chinese input method editor has operated a persistent, multi-tier asset-delivery pipeline since at least 2018, routing advertisement images and remotely controlled JSON payloads through a consistent saXXXX.tmp staging pattern. The campaign's MITRE technique profile — including sandbox evasion, NTFS alternate data stream hiding, and security tool impairment — far exceeds what ad injection requires, and every artifact in the corpus has maintained zero antivirus detections across 68–77 engines throughout its documented lifespan.

Jun 11, 2026, 16:10 (UTC+9)Last seenJun 11, 2026Severity92ByCTX TeamIOC49MITRE24RegionsHK

A Chinese-language input method editor has been quietly running a multi-tier asset-delivery pipeline on victim hosts since at least 2018 — one whose technical fingerprints look considerably more sophisticated than the advertisement injection it ostensibly exists to perform. The 2345Pinyin IME client, distributed by Shanghai 2345 Network Technology Co., Ltd.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence