'Harmless' Global Adware Transforms Into an AV Killer
ID: 5e1fbc14-bb53-522b-9676-01e204ec544f
STIX ID: report--5e1fbc14-bb53-522b-9676-01e204ec544f
Feed Name: Dark Reading
The report details how Dragon Boss Solutions LLC distributed adware that received a malicious update on March 22, 2025 which disabled antivirus products (ESET, McAfee, Kaspersky, Malwarebytes), created persistence (scheduled tasks), and added Windows Defender exclusions, effectively backdooring roughly 23,500 systems across 124 countries including government, OT networks, higher education, and some Fortune 500 companies; Huntress researchers registered/sinkholed the campaign's primary update domain to mitigate further misuse. The write-up highlights the ease of abusing update mechanisms for follow-on malware (ransomware, botnets), the blurred line between PUPs and malware, and the need to block or monitor ad/update channels.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
