logo

25,000+ Endpoints Left Exposed In Dragon Boss Solutions Domain Update Breach

ID: 6ae112cd-82ff-5d88-9427-aeb4316aece5

STIX ID: report--6ae112cd-82ff-5d88-9427-aeb4316aece5

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-04-15

Date Updated: 2026-05-05

Author: Varshini

...
...

Huntress uncovered that Dragon Boss Solutions–signed adware leveraged a hijackable update domain (chromsterabrowser.com) to push AV‑killing PowerShell payloads and code‑signed binaries, exposing over 25,000 endpoints across 124 countries and impacting sensitive networks; by registering the domain for roughly $10 and sinkholing traffic, researchers confirmed the updater would fetch and execute arbitrary MSI payloads, turning ostensibly benign adware into a high‑risk supply‑chain threat and urging defenders to hunt for signed binaries, WMI subscriptions, scheduled tasks, Defender exclusions, and hosts‑file tampering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.