As cited
Copy frozen at (site build).
threat intel
When PUPs Grow Fangs: Dragon Boss Solutions' $10 Supply Chain Risk
Huntress discovered a malware operation leveraging a signed potentially unwanted program (PUP) to deploy antivirus killing tools with SYSTEM level privileges. The attack exploited the supply chain through a compromised update mechanism, allowing threat actors to distribute malware while maintaining legitimate code signatures.
Why it matters: Any organization running this signed PUP faces immediate risk of antivirus bypass and full system compromise; practitioners should audit for this PUP and review signed executable allowlists for similar supply chain weaknesses.
- Source published
- First seen by Cybersecurity Tracker