INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Lazarus Group Deploys Signed Adware to Disable Antivirus Software

| 2026-04-15 14:40 MEDIUM HIGH STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A signed software operation linked to Dragon Boss Solutions LLC has reportedly been silently disabling antivirus products on more than 23,000 endpoints worldwide. The campaign used a legitimate code-signing certificate and an off-the-shelf update mechanism to deploy a PowerShell-based payload that systematically kills, uninstalls and blocks the reinstallation of security tools. This attack works by first checking for admin status, detecting virtual machines and querying the registry for installed security products before establishing persistence across reboots, logons and at 30-minute intervals. The current status is that Huntress researchers have identified 324 infections on high-value networks, including universities (221), operational technology networks (41) and government entities (35), with infections spanning 124 countries, primarily in the US (54%), France, Canada, the UK, and Germany.
Technical Mitigations AI-generated
• Patch Dragon Boss Solutions' Advanced Installer to prevent MSI-based updates from being used for malicious purposes. • Block ClockRemoval.ps1 script execution with SYSTEM privileges by configuring Windows Firewall rules or using a host-based intrusion detection system (HIDS). • Monitor WMI event subscriptions and scheduled tasks created by the payload, and block any suspicious activity.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation Disables AntivirusOperation Disables Antivirus
Target & Sectors
NORTH_AMERICA NORTH_AMERICA DACH DACH educationeducation
Incident Timeline
‎March 2025
Threat actors used a signed adware operation to disable antivirus software across 23,000 hosts within 24 hours of requesting instructions from 23,565 unique IP addresses.
infrastructure Windows
infrastructure 0.0.0
infrastructure 23,565 unique IP addresses
‎2026/04/15
A signed software operation linked to Dragon Boss Solutions LLC has deployed a PowerShell-based payload that systematically kills, uninstalls and blocks the reinstallation of security tools on more than 23,000 endpoints worldwide.
infrastructure 23,000 Hosts
Tactical Metrics
Metrics
infrastructure
23,000
Hosts
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎0.0.0
Software Version
Metrics
infrastructure
23,565
Unique Ip Addresses
Intelligence Sources
Infosecurity-Magazine 2026-04-15
Infosecurity-Magazine 2026-04-15