Dragon Boss Solutions' Signed Adware Disables Antivirus on 25,000+ Endpoints

Dragon Boss Solutions' Signed Adware Disables Antivirus on 25,000+ Endpoints

First seen 15 Apr 2026, 05:58 UTC HuntressCybersecuritynewsInfosecurity-MagazineBleepingcomputerTechnadu+2 82% similarity 71.0

Article Content

Browse articles
ThreatCluster

On March 22, 2026, Huntress identified a campaign involving signed adware from Dragon Boss Solutions LLC that disabled antivirus protections on over 23,500 endpoints across 124 countries. The software, marketed as potentially unwanted programs (PUPs), utilized a sophisticated update mechanism to deploy malicious payloads with SYSTEM privileges. The adware's update process, based on the Advanced Installer tool, executed PowerShell scripts to disable security products from major vendors like Malwarebytes and Kaspersky. The malicious payloads were disguised as benign files, and the operation's infrastructure included an unregistered domain that could be exploited for further attacks. The incident highlights a significant supply chain risk, as anyone could register the domain to push harmful updates. Huntress has since registered the domain to prevent further exploitation. The attack primarily affected sectors including education, utilities, government, and healthcare.

Key Points: • Over 23,500 endpoints were compromised globally due to signed adware from Dragon Boss Solutions. • The adware uses an advanced update mechanism to deploy malicious payloads that disable antivirus software. • Huntress registered the malicious update domain to prevent further exploitation.

ThreatCluster AI

Timeline

2026-03-22
Huntress discovers the adware campaign disabling antivirus protections.
2026-04-14
Huntress publishes detailed analysis of the Dragon Boss Solutions attack.
2026-04-15
Bleepingcomputer reports on the widespread impact of the adware.

Community

Browse all →