logo

25,000+ Endpoints Exposed by Dragon Boss Solutions Update Domain Supply Chain Attack

ID: 8bf318a7-7a80-5e8d-8e95-6b65a730eff5

STIX ID: report--8bf318a7-7a80-5e8d-8e95-6b65a730eff5

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-15

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

### Executive summary A widespread malware campaign abused signed updater software from "Dragon Boss Solutions LLC" to silently deploy an AV-killing PowerShell payload (ClockRemoval.ps1) via MSI/PowerShell installers and WMI persistence; tens of thousands of infected systems worldwide—including critical infrastructure and academic networks—queried an unregistered update domain that could have allowed arbitrary payload delivery to all victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.