Dragon Boss Solutions LLC adware malicious update
Malware Activity
Summary
Hide ▲
Show ▼
A March 22, 2025 malicious update turned Dragon Boss Solutions LLC adware into an AV-disabling payload, exposing nearly 24,000 systems to follow-on abuse. The update targeted security tools from ESET, McAfee, Kaspersky, and Malwarebytes, and it also added scheduled-task persistence and Windows Defender exclusions. The malware was later found on 23,500+ computers in 124 countries, including 35 government entities and 41 OT networks.
Related Happenings
Daemon Tools Lite trojanized installer campaign
Campaign
First: 07.05.2026 12:30
Last: 07.05.2026 12:30
Sources 1
About this happening:
A **trojanized Daemon Tools Lite installer campaign** is driving **several thousand infection attempts** across **more than 100 countries**, turning a trusted download into a malw...
Daemon Tools Lite trojanized installer campaign
CampaignAbout this happening: A **trojanized Daemon Tools Lite installer campaign** is driving **several thousand infection attempts** across **more than 100 countries**, turning a trusted download into a malw...
DAEMON Tools Lite trojanized installer wave
Exploitation Wave
First: 06.05.2026 19:43
Last: 06.05.2026 19:43
Sources 1
About this happening:
Trojanized **DAEMON Tools Lite** installers backdoored **thousands of systems** in **more than 100 countries**, turning a trusted download path into a broad infection wave. The co...
DAEMON Tools Lite trojanized installer wave
Exploitation WaveAbout this happening: Trojanized **DAEMON Tools Lite** installers backdoored **thousands of systems** in **more than 100 countries**, turning a trusted download path into a broad infection wave. The co...
DAEMON Tools trojanized-installer stealer and backdoor activity
Malware Activity
First: 05.05.2026 22:21
Last: 05.05.2026 22:21
Sources 1
About this happening:
A **DAEMON Tools** supply-chain compromise is delivering **trojanized installers** that install a **backdoor** and steal system data from downloaded systems. The activity has run...
DAEMON Tools trojanized-installer stealer and backdoor activity
Malware ActivityAbout this happening: A **DAEMON Tools** supply-chain compromise is delivering **trojanized installers** that install a **backdoor** and steal system data from downloaded systems. The activity has run...
Sqgame[.]net gaming platform hit by network compromise
Incident
First: 05.05.2026 18:00
Last: 05.05.2026 18:00
Sources 1
About this happening:
The **sqgame[.]net** gaming platform was **compromised**, and its **Windows** and **Android** software were **trojanized** to deliver malicious code to users, putting a regional e...
Sqgame[.]net gaming platform hit by network compromise
IncidentAbout this happening: The **sqgame[.]net** gaming platform was **compromised**, and its **Windows** and **Android** software were **trojanized** to deliver malicious code to users, putting a regional e...
BirdCall Android spyware variant
Malware Activity
First: 05.05.2026 12:04
Last: 05.05.2026 12:04
Sources 1
About this happening:
The **BirdCall** Android spyware variant expanded a known **Windows** backdoor into a mobile surveillance tool with **file exfiltration** and device reconnaissance capabilities. I...
BirdCall Android spyware variant
Malware ActivityAbout this happening: The **BirdCall** Android spyware variant expanded a known **Windows** backdoor into a mobile surveillance tool with **file exfiltration** and device reconnaissance capabilities. I...
Timeline
-
16.04.2026 22:07 2 articles · 1mo ago
Dragon Boss Solutions LLC pushes AV-disabling update
Technical Analysis UpdateDragon Boss Solutions LLC pushes a malicious Advanced Installer update to its adware on March 22, 2025, disabling ESET, McAfee, Kaspersky, and Malwarebytes detection, adding scheduled-task persistence, and setting Windows Defender exclusions that could let future payloads land with less resistance.
Show sources
- 'Harmless' Global Adware Transforms Into an AV Killer — www.darkreading.com — 16.04.2026 22:07
- 'Harmless' Global Adware Transforms Into an AV Killer — www.darkreading.com — 16.04.2026 22:07
-
16.04.2026 22:07 1 articles · 1mo ago
Huntress sinkholes Dragon Boss update domain and measures spread
Campaign Scope UpdateHuntress sinkholes the campaign's primary update domain and finds Dragon Boss adware on more than 23,500 computers in 124 countries, including 35 government entities, 41 operational technology networks, and 221 higher education institutions, showing a broad distribution base for follow-on cyberattacks.
Show sources
- 'Harmless' Global Adware Transforms Into an AV Killer — www.darkreading.com — 16.04.2026 22:07