Signed Adware Turns Update Channels Into AV Killers
Legitimate signed update channels can become fleet-wide attack paths. Here, the standard response of treating a PUP as nuisance software misses the real risk: the installer runs as SYSTEM, kills security tools, and keeps coming back through persistence that survives reboots and logons.
Huntress says Dragon Boss Solutions LLC–signed executables were used to deploy ClockRemoval.ps1 across more than 23,000 endpoints in 124 countries. The payload targeted Malwarebytes, Kaspersky, McAfee, and ESET, used scheduled tasks and WMI subscriptions for persistence, and could block reinstallation after removing AV.
The deeper problem is trust in signed software and managed update flows. If an attacker can reach the update source or abuse the same mechanism, they can push arbitrary payloads to affected hosts and keep security controls down long enough to stage follow-on activity.