logo

Signed software abused to deploy antivirus-killing scripts

ID: 9cec2de8-1365-570d-80ea-85cc514677b5

STIX ID: report--9cec2de8-1365-570d-80ea-85cc514677b5

Feed Name: Bleeping Computer

Threat Score
82/100

Date Published: 2026-04-15

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A digitally signed adware product from Dragon Boss Solutions (promoting browser-like PUPs such as Chromnius) abused Advanced Installer's update mechanism to silently deploy MSI and PowerShell payloads (disguised as images) that install with SYSTEM privileges and run ClockRemoval.ps1 to stop/uninstall AV products, block vendor domains, and maintain persistence. Huntress observed over 23,500 infected hosts across 124 countries, including hundreds in high-value networks (academic, OT, government, healthcare, Fortune 500), and sinkholed the unregistered update domain to prevent further malicious instructions; recommended hunt items include WMI subscriptions, scheduled tasks, hosts file entries blocking AV domains, and suspicious Defender exclusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.