JAVS courtroom recording software backdoored in supply chain attack
ID: 6498eb10-2af0-583f-97ef-c716bfc40ecd
STIX ID: report--6498eb10-2af0-583f-97ef-c716bfc40ecd
Feed Name: Bleeping Computer
Attackers trojanized the installer for Justice AV Solutions (JAVS) courtroom video software (version 8.3.7) by embedding a malicious fffmpeg.exe dropper linked to Rustdoor/GateDoor; the malware phones home to a C2, executes obfuscated PowerShell to disable ETW and bypass AMSI, and then downloads Python scripts to steal browser credentials. Rapid7 and JAVS advise reimaging potentially affected systems, resetting credentials, and upgrading to Viewer 8.3.9 or later to remove persistence and prevent further compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
