Signed software abused to deploy antivirus-killing scripts
ID: 9cec2de8-1365-570d-80ea-85cc514677b5
STIX ID: report--9cec2de8-1365-570d-80ea-85cc514677b5
Feed Name: Bleeping Computer
A digitally signed adware product from Dragon Boss Solutions (promoting browser-like PUPs such as Chromnius) abused Advanced Installer's update mechanism to silently deploy MSI and PowerShell payloads (disguised as images) that install with SYSTEM privileges and run ClockRemoval.ps1 to stop/uninstall AV products, block vendor domains, and maintain persistence. Huntress observed over 23,500 infected hosts across 124 countries, including hundreds in high-value networks (academic, OT, government, healthcare, Fortune 500), and sinkholed the unregistered update domain to prevent further malicious instructions; recommended hunt items include WMI subscriptions, scheduled tasks, hosts file entries blocking AV domains, and suspicious Defender exclusions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
