The Dragon Boss Solutions malware operation utilized a legitimately signed potentially unwanted program (PUP) to silently deploy AV killer malware with SYSTEM privileges across thousands of networks. The adware's automated update mechanism contained a critical flaw: its primary update domain, chromsterabrowser.com, remained unregistered. This oversight created a massive supply chain attack vector.
Any threat actor who registered the domain could have pushed arbitrary, malicious payloads to more than 25,000 infected endpoints without requiring further exploitation. Security researchers successfully sinkholed the domain, preventing immediate exploitation.
Once installed, the Dragon Boss Solutions malware executes a PowerShell script designated as ClockRemoval.ps1, the latest Huntress report said . This payload actively targets and disables prominent security products, including Malwarebytes, Kaspersky, McAfee, and ESET.
It establishes persistent access via Windows Management Instrumentation (WMI) event subscriptions and recurring scheduled tasks, ensuring the antivirus (AV) killer malware runs continuously. Furthermore, the script modifies host files to block AV update domains and adds Windows Defender exclusions to protect its payload staging directories.
CrunchBase listing for “Dragon Boss Solutions” | Source: Huntress
The telemetry identified 324 infections within high-value environments based on the IP addresses observed, including operational technology (OT) networks, government entities, and universities, including:
During a 24-hour observation period, the sinkholed domain recorded connections from thousands of unique IP addresses globally. Huntress observed the antivirus killing capability starting in late March 2025, although the loaders/updaters dated back to late 2024.
This incident highlights the severe cybersecurity risks associated with PUPs, demonstrating how aggressively standard adware can evolve into a critical system-level vulnerability.
Last week, the NHS Scotland domain was breached to host adult content and illegal sports streams. Last year, the EPI PDF Editor tool posed as a PDF converter but instead hijacked Internet browsers.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
