Threats · 153 days ago
Legitimate signed update channels can become fleet-wide attack paths. Here, the standard response of treating a PUP as nuisance software misses the real risk: the installer runs as SYSTEM, kills security tools, and keeps coming back through persistence that survives reboots and logons.
Huntress says Dragon Boss Solutions LLC–signed executables were used to deploy ClockRemoval.ps1 across more than 23,000 endpoints in 124 countries. The payload targeted Malwarebytes, Kaspersky, McAfee, and ESET, used scheduled tasks and WMI subscriptions for persistence, and could block reinstallation after removing AV.
The deeper problem is trust in signed software and managed update flows. If an attacker can reach the update source or abuse the same mechanism, they can push arbitrary payloads to affected hosts and keep security controls down long enough to stage follow-on activity.
2 sources covering this story
Signed Adware Operation Disables Antivirus Across 23,000 Hosts
Huntress uncovers adware deploying AV-killing payloads via signed updates across 23,000 endpoints
Signed software abused to deploy antivirus-killing scripts
A digitally signed adware tool has deployed payloads running with SYSTEM privileges that disabled antivirus protections on thousands of endpoints, some in the educational, utilities, government, and healthcare sectors.
Part of the PlainSec briefing for 2026-05-04