logo

JAVS Courtroom Recording Software Backdoored - Deploys RustDoor Malware

ID: 857d0813-f940-5587-92cb-5cfb688ca76f

STIX ID: report--857d0813-f940-5587-92cb-5cfb688ca76f

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-05-24

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

A trojanized installer for Justice AV Solutions (JAVS) Viewer v8.3.7 was discovered containing a malicious executable (fffmpeg.exe) signed with an unexpected Authenticode certificate and used to deploy a RustDoor/GateDoor Windows backdoor. The binary executed obfuscated PowerShell to bypass AMSI/ETW, contacted C2 servers, downloaded additional payloads (including a faux Chrome installer and main.exe), and attempted to harvest browser credentials; Rapid7 and other vendors traced the compromise to an installer downloaded from the official site, and JAVS removed the affected version and reset credentials. Indicators of compromise and remediation advice (re-image, reset credentials, update to patched viewer) were provided, and infrastructure links to a RaaS affiliate (ShadowSyndicate) were noted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.