25,000+ Endpoints Exposed by Dragon Boss Solutions Update Domain Supply Chain Attack
ID: 8bf318a7-7a80-5e8d-8e95-6b65a730eff5
STIX ID: report--8bf318a7-7a80-5e8d-8e95-6b65a730eff5
Feed Name: cybersecurityNews.com
Threat Score
### Executive summary A widespread malware campaign abused signed updater software from "Dragon Boss Solutions LLC" to silently deploy an AV-killing PowerShell payload (ClockRemoval.ps1) via MSI/PowerShell installers and WMI persistence; tens of thousands of infected systems worldwide—including critical infrastructure and academic networks—queried an unregistered update domain that could have allowed arbitrary payload delivery to all victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
