When PUPs Grow Fangs: Dragon Boss Solutions' $10 Supply Chain Risk

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Huntress researchers uncovered a malware operation by Dragon Boss Solutions LLC, a company distributing signed PUPs (potentially unwanted programs) that secretly deploy a sophisticated AV-killing PowerShell payload (ClockRemoval.ps1) via a legitimate software update mechanism. The payload disables and uninstalls security products like Malwarebytes, ESET, Kaspersky, and McAfee; blocks their update domains via the hosts file; establishes WMI and scheduled task persistence; and adds Windows Defender exclusions for future payload staging. Critically, the primary update domain (chromsterabrowser[.]com) was unregistered, meaning anyone spending $10 to register it could push arbitrary payloads to all infected hosts. Huntress registered the domain first, sinkholed it, and observed over 23,500 unique infected endpoints across 124 countries — including universities, government agencies, OT networks, and Fortune 500 companies — reaching out within 24 hours. Detection guidance and full IOCs are provided.

17m read timeFrom huntress.com
Post cover image
Table of contents
BackgroundSetting the stageInitial discoveryThe update mechanismPayload analysisClockRemoval.ps1: The AV killerThe threat actor: Dragon Boss Solutions LLCSo what did Huntress do?StatisticsConclusionIndicators of Compromise
2 Impressions