
2345Pinyin IME Runs Six-Year Covert Delivery Pipeline Behind Ad-Injection Cover
The 2345Pinyin Chinese input method editor has operated a persistent, multi-tier asset-delivery pipeline since at least 2018, routing advertisement images and remotely controlled JSON payloads through a consistent saXXXX.tmp staging pattern. The campaign's MITRE technique profile — including sandbox evasion, NTFS alternate data stream hiding, and security tool impairment — far exceeds what ad injection requires, and every artifact in the corpus has maintained zero antivirus detections across 68–77 engines throughout its documented lifespan.
A Chinese-language input method editor has been quietly running a multi-tier asset-delivery pipeline on victim hosts since at least 2018 — one whose technical fingerprints look considerably more sophisticated than the advertisement injection it ostensibly exists to perform. The 2345Pinyin IME client, distributed by Shanghai 2345 Network Technology Co., Ltd.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read