Suspected supply chain attack backdoors courtroom recording software
ID: 6fba4105-8e4c-5671-b7a9-299eeee37a44
STIX ID: report--6fba4105-8e4c-5671-b7a9-299eeee37a44
Feed Name: The Register (Security)
Rapid7 investigated a suspected supply-chain compromise of Justice AV Solutions' JAVS Viewer installer (v8.3.7) after a malicious binary named "fffmpeg.exe" was found to provide C2 remote access and is linked to the GateDoor/Rustdoor family (CVE-2024-4978). The backdoor enabled execution of obfuscated PowerShell, disabling of Event Tracing for Windows, additional payload downloads, and browser credential theft; Rapid7 advises reimaging affected endpoints, resetting local and remote credentials (including browser-stored credentials), and only then installing the patched JAVS Viewer (8.3.9 or later).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
