INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Lazarus Group Deploys Signed Adware to Disable Antivirus Software
| 2026-04-15 14:40 MEDIUM HIGH STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A signed software operation linked to Dragon Boss Solutions LLC has reportedly been silently disabling antivirus products on more than 23,000 endpoints worldwide. The campaign used a legitimate code-signing certificate and an off-the-shelf update mechanism to deploy a PowerShell-based payload that systematically kills, uninstalls and blocks the reinstallation of security tools. This attack works by first checking for admin status, detecting virtual machines and querying the registry for installed security products before establishing persistence across reboots, logons and at 30-minute intervals. The current status is that Huntress researchers have identified 324 infections on high-value networks, including universities (221), operational technology networks (41) and government entities (35), with infections spanning 124 countries, primarily in the US (54%), France, Canada, the UK, and Germany.
Technical Mitigations AI-generated
• Patch Dragon Boss Solutions' Advanced Installer to prevent MSI-based updates from being used for malicious purposes.
• Block ClockRemoval.ps1 script execution with SYSTEM privileges by configuring Windows Firewall rules or using a host-based intrusion detection system (HIDS).
• Monitor WMI event subscriptions and scheduled tasks created by the payload, and block any suspicious activity.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation Disables AntivirusOperation Disables Antivirus
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
DACH
DACH
educationeducation
Incident Timeline
March 2025
Threat actors used a signed adware operation to disable antivirus software across 23,000 hosts within 24 hours of requesting instructions from 23,565 unique IP addresses.
Click on any entity below to view its context and source!
infrastructure
Windows
It then establishes five scheduled tasks and Windows Management Instrumentation (WMI) event subscriptions that maintain persistence across reboots, logons and at 30-minute intervals.
The script also strips registry entries, runs vendor uninstallers silently and modifies the Windows hosts file to redirect AV update domains to 0.0.0.0.
infrastructure
0.0.0
The script also strips registry entries, runs vendor uninstallers silently and modifies the Windows hosts file to redirect AV update domains to 0.0.0.0.
infrastructure
23,565 unique IP addresses
Within 24 hours, 23,565 unique IP addresses requested instructions.
2026/04/15
A signed software operation linked to Dragon Boss Solutions LLC has deployed a PowerShell-based payload that systematically kills, uninstalls and blocks the reinstallation of security tools on more than 23,000 endpoints worldwide.
Click on any entity below to view its context and source!
infrastructure
23,000 Hosts
Signed Adware Operation Disables Antivirus Across 23,000 Hosts.
A signed software operation linked to a company called Dragon Boss Solutions LLC has reportedly been silently disabling antivirus products on more than 23,000 endpoints worldwide
According to
research
published by Huntress on Tuesday, the campai…
Tactical Metrics
Metrics
infrastructure
23,000
Hosts
Click for context!
Signed Adware Operation Disables Antivirus Across 23,000 Hosts.
A signed software operation linked to a company called Dragon Boss Solutions LLC has reportedly been silently disabling antivirus products on more than 23,000 endpoints worldwide
According to
research
published by Huntress on Tuesday, the campai…
Metrics
infrastructure
Windows
Affected Product
It then establishes five scheduled tasks and Windows Management Instrumentation (WMI) event subscriptions that maintain persistence across reboots, logons and at 30-minute intervals.
The script also strips registry entries, runs vendor uninstallers silently and modifies the Windows hosts file to redirect AV update domains to 0.0.0.0.
Metrics
infrastructure
0.0.0
Software Version
The script also strips registry entries, runs vendor uninstallers silently and modifies the Windows hosts file to redirect AV update domains to 0.0.0.0.
Metrics
infrastructure
23,565
Unique Ip Addresses
Within 24 hours, 23,565 unique IP addresses requested instructions.
Intelligence Sources
Infosecurity-Magazine
2026-04-15
Signed Adware Operation Disables Antivirus Across 23,000 Hosts
Infosecurity-Magazine
Infosecurity-Magazine
2026-04-15
Signed Adware Operation Disables Antivirus Across 23,000 Hosts
Infosecurity-Magazine
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T11:49
Comprehensive Tactical Telemetry
Highly Correlated Entities
13x
organisation
Identified Entity
Infections
entity
5x
target region
Target Country
United States
country
3x
industry
Targeted Sector
Technology
sector
2x
tactic
MITRE ATT&CK Technique
T1047 - Windows Management Instrumentation
technique
2x
timeline
Temporal Reference
late March 2025
date
Contextual Telemetry
Context Block
18 METRICS
general metric
Countries
124
countries
general metric
%
54
%
source region
Origin Country
United Arab Emirates
country
attribution
Attributing Entity
CrunchBase
authority
general metric
Infections
324
infections
general metric
Universities
221
universities
general metric
Operational Technology Networks
41
operational technology networks
general metric
Government Entities
35
government entities
tactic
Cyber Operation Type
Ransomware
tactic
campaign
Campaign
Operation Disables Antivirus
operation
infrastructure
Hosts
23,000
hosts
infrastructure
Affected Product
Windows
software
general metric
Minute
30
minute
infrastructure
Software Version
0.0.0
version
general metric
Milliseconds
100
milliseconds
general metric
Seconds
20
seconds
general metric
Hours
24
hours
infrastructure
Unique Ip Addresses
23,565
unique ip addresses
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.