logo

JDownloader Site Breach Installs Rootkits that Kill Your Antivirus

ID: ec6609e6-3abe-5684-8393-a76dd658f2ea

STIX ID: report--ec6609e6-3abe-5684-8393-a76dd658f2ea

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: Ddos

...
...

In a May 6–7, 2026 supply‑chain compromise of the official JDownloader website, attackers replaced official installers with malicious variants that deploy a five‑component framework (PyArmor bot, PyArmor runtime DLL, r77 rootkit stager, WDAC deny‑list policy, and Python installer). The campaign uses a CMS exploit to deliver a dropper that evades automated sandboxes, installs a WDAC policy to block many AV products, hides artifacts via the r77 rootkit ($77 prefix), and employs Dead‑Drop Resolvers plus a DGA for C2 resilience; remediation notes include removing unauthorized SIPolicy.p7b and performing a full OS reinstall for complete recovery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.