logo

When Trust Becomes a Trap: How Huntress Foiled a Medical Software Update Hack | Huntress

ID: 98431ff8-562b-51bd-aa8e-050c89ff990b

STIX ID: report--98431ff8-562b-51bd-aa8e-050c89ff990b

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2024-07-23

Date Updated: 2026-04-28

...
...

Huntress discovered attackers cloned the MicroDicom website and distributed a fake 178MB installer (served from S3 and linked from domains such as mLcrodLcom.info and similar variants) that bundled OpenSSH and installed a persistent UpdaterSvc.exe and 7655.bat to create SSH tunnels to an attacker-controlled server; multiple medical endpoints executed the installer, enabling remote shell access and potential exfiltration of patient data. Indicators include the malicious domains, S3-hosted binary, UpdaterSvc.exe, 7655.bat, and the presence of OpenSSH bundled in the installer.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.