25,000+ Endpoints Left Exposed In Dragon Boss Solutions Domain Update Breach
ID: 6ae112cd-82ff-5d88-9427-aeb4316aece5
STIX ID: report--6ae112cd-82ff-5d88-9427-aeb4316aece5
Feed Name: Cyber Press
Huntress uncovered that Dragon Boss Solutions–signed adware leveraged a hijackable update domain (chromsterabrowser.com) to push AV‑killing PowerShell payloads and code‑signed binaries, exposing over 25,000 endpoints across 124 countries and impacting sensitive networks; by registering the domain for roughly $10 and sinkholing traffic, researchers confirmed the updater would fetch and execute arbitrary MSI payloads, turning ostensibly benign adware into a high‑risk supply‑chain threat and urging defenders to hunt for signed binaries, WMI subscriptions, scheduled tasks, Defender exclusions, and hosts‑file tampering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
