Signed Adware Operation Disables Antivirus Across 23,000 Hosts
ID: 51ce473e-0963-5eb8-aa0d-a9538ecf7c1f
STIX ID: report--51ce473e-0963-5eb8-aa0d-a9538ecf7c1f
Feed Name: Infosecurity Magazine (News)
Huntress tracked a global campaign using a legitimately signed updater tied to Dragon Boss Solutions LLC to push a PowerShell-based AV-killer (ClockRemoval.ps1) that kills and uninstalls security products, establishes persistence via scheduled tasks and WMI subscriptions, and redirects AV update domains; sinkholing the unregistered update domain revealed 23,565 unique IPs across 124 countries including universities, OT networks, and government hosts, and warned the infrastructure could deliver ransomware, cryptomining, or data theft payloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
