{"id":12123,"date":"2026-04-15T10:03:36","date_gmt":"2026-04-15T10:03:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/15\/25000-endpoints-exposed-by-dragon-boss-solutions-update-domain-supply-chain-attack\/"},"modified":"2026-04-15T10:03:36","modified_gmt":"2026-04-15T10:03:36","slug":"25000-endpoints-exposed-by-dragon-boss-solutions-update-domain-supply-chain-attack","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/15\/25000-endpoints-exposed-by-dragon-boss-solutions-update-domain-supply-chain-attack\/","title":{"rendered":"25,000+ Endpoints Exposed by Dragon Boss Solutions Update Domain Supply Chain Attack"},"content":{"rendered":"<p>    25,000+ Endpoints Exposed by Dragon Boss Solutions Update Domain Supply Chain Attack<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>What started as a routine adware alert quickly turned into something far more serious. <\/p>\n<p>On the morning of March 22, 2026, security alerts began firing across multiple managed environments, all linked to software signed by a company called Dragon Boss Solutions LLC. <\/p>\n<p>The executables looked harmless at first glance, but they were quietly using a built-in update mechanism to carry out a multi-stage attack designed to kill antivirus tools and leave systems completely unprotected.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/363ddd4b-3c36-4f63-8869-0e7e0650fd0c\/25000-Endpoints-Exposed-by-Dragon-Boss-Solutions-Update-Domain-Supply-Chain-Attack.pdf?AWSAccessKeyId=ASIA2F3EMEYE6G7GT6D3&amp;Signature=G%2BU0uMFbOSRctKBMuFsNBtNG94Y%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjENX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDKPg9t94zE1YiOu0FOiUGWoJjbj37uwUk1II9pnKIlxwIhAJz1Ym8CX54wumNE%2BqptwkW%2Fi6wzCnkXniX7w0DaMdSeKvwECJ7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgxiNA7MlLuHjZ8KoH0q0AS%2FQH%2BEvAKXaBp%2BYhjijoLWhO3yrcRWp9amNmyqbie2pEbRWwm%2FMAJUHpWgyLu5MI3G10MkDYBh1pEkKwjFo%2BJYoh48OFIc3ubLjrl47Pu9Ax2cTM5Gfjx0Hahj45uUj1KmhAwA5nD3RyHwTFSgJ41fhTP8tgCichanCJZWvKlYw3CtbFcxQtY48V%2Bn2QkB6%2BfdJpAL%2BOLLocMMtsErybfziQLmbufGdOhv1FtM61MwxNlaTwiLIpKyQgAEnMspAxkc%2BTVRPAZ7krxo6I%2B8ZNIMXQOj9v3wQCaZT3KKKDqPtDfAuHczxI3PqtQ9po22BmRrlY1kyKUuYivoaLO4Uljh3Yo1zjlC0X%2F20u0mexNOvkamQ%2F%2BLcqk9f0cVpynvhoNwNnienZ%2FStLOBPhN0pg9b%2F710m5X61AAddKBZAAbqSIA%2FE1UqhKpsKJrMffSe6mUZVS2wUbQqZ2iqaacE0%2FAHWiMmoOd%2FUa2So9m%2FgqJbw36SA5zMBCFlIxxkQD7XSr85%2ByroQGa6DFJOH9%2FBhJlg3JKd2eWND9eq9Mh9bBDOZRswUoSKNwETzHwT1NnXA2ASnBmo48k03sMC6gM8we8wePVt%2FYOUvQAGN9fa5Be1W0bqJ3bDMb5Q4obwqrIsmH%2Bk96g5Fxfr7IBd89fXiajNSV6zWewfi03Jtp3gZzznPCSWxoLiZl8GKXUbuHOIqqEPk2p%2FQq%2F6kOlTSqpDzXMSIJUkPoRdUMdHS43n4tcWtjmMCtEATtkpDTubPvptq0VtJhOZQ3qIkYcBwEpsY6PsMKOw%2FM4GOpcBhqDxOTje6woZrC9Ylv83NdlkolngRWQd7cs6ka34fuK0sMt%2BOMhm2oz9Ktqw8GJ7naiHyEcVlxxFG1ReMvCzkH6CfMb5BbB4%2FwuYnv62Q9KTefqd1oGqzs7Vu69%2BDUtHBJsYEeDY2Q0Sz0uLQ7nshj5Ap0jMTNJrXebwQyw4BHj56jfPboHWjWHN0OFDw3KO56KKB8mAiw%3D%3D&amp;Expires=1776230009\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Dragon Boss Solutions LLC presents itself as a company engaged in \u201csearch monetization research.\u201d Its signed software, however, had a much darker purpose. <\/p>\n<p>Running with full SYSTEM privileges, these executables silently fetched and deployed payloads capable of disabling security products across infected machines. <\/p>\n<p>The antivirus-killing behavior was first observed in late March 2025, though the underlying loaders and updaters had been present on victim systems since late 2024. <\/p>\n<p>The operation used Advanced Installer, a legitimate off-the-shelf update tool, to deliver MSI and PowerShell-based payloads while hiding behind a layer of apparent legitimacy.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/363ddd4b-3c36-4f63-8869-0e7e0650fd0c\/25000-Endpoints-Exposed-by-Dragon-Boss-Solutions-Update-Domain-Supply-Chain-Attack.pdf?AWSAccessKeyId=ASIA2F3EMEYE6G7GT6D3&amp;Signature=G%2BU0uMFbOSRctKBMuFsNBtNG94Y%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjENX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDKPg9t94zE1YiOu0FOiUGWoJjbj37uwUk1II9pnKIlxwIhAJz1Ym8CX54wumNE%2BqptwkW%2Fi6wzCnkXniX7w0DaMdSeKvwECJ7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgxiNA7MlLuHjZ8KoH0q0AS%2FQH%2BEvAKXaBp%2BYhjijoLWhO3yrcRWp9amNmyqbie2pEbRWwm%2FMAJUHpWgyLu5MI3G10MkDYBh1pEkKwjFo%2BJYoh48OFIc3ubLjrl47Pu9Ax2cTM5Gfjx0Hahj45uUj1KmhAwA5nD3RyHwTFSgJ41fhTP8tgCichanCJZWvKlYw3CtbFcxQtY48V%2Bn2QkB6%2BfdJpAL%2BOLLocMMtsErybfziQLmbufGdOhv1FtM61MwxNlaTwiLIpKyQgAEnMspAxkc%2BTVRPAZ7krxo6I%2B8ZNIMXQOj9v3wQCaZT3KKKDqPtDfAuHczxI3PqtQ9po22BmRrlY1kyKUuYivoaLO4Uljh3Yo1zjlC0X%2F20u0mexNOvkamQ%2F%2BLcqk9f0cVpynvhoNwNnienZ%2FStLOBPhN0pg9b%2F710m5X61AAddKBZAAbqSIA%2FE1UqhKpsKJrMffSe6mUZVS2wUbQqZ2iqaacE0%2FAHWiMmoOd%2FUa2So9m%2FgqJbw36SA5zMBCFlIxxkQD7XSr85%2ByroQGa6DFJOH9%2FBhJlg3JKd2eWND9eq9Mh9bBDOZRswUoSKNwETzHwT1NnXA2ASnBmo48k03sMC6gM8we8wePVt%2FYOUvQAGN9fa5Be1W0bqJ3bDMb5Q4obwqrIsmH%2Bk96g5Fxfr7IBd89fXiajNSV6zWewfi03Jtp3gZzznPCSWxoLiZl8GKXUbuHOIqqEPk2p%2FQq%2F6kOlTSqpDzXMSIJUkPoRdUMdHS43n4tcWtjmMCtEATtkpDTubPvptq0VtJhOZQ3qIkYcBwEpsY6PsMKOw%2FM4GOpcBhqDxOTje6woZrC9Ylv83NdlkolngRWQd7cs6ka34fuK0sMt%2BOMhm2oz9Ktqw8GJ7naiHyEcVlxxFG1ReMvCzkH6CfMb5BbB4%2FwuYnv62Q9KTefqd1oGqzs7Vu69%2BDUtHBJsYEeDY2Q0Sz0uLQ7nshj5Ap0jMTNJrXebwQyw4BHj56jfPboHWjWHN0OFDw3KO56KKB8mAiw%3D%3D&amp;Expires=1776230009\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p><a href=\"https:\/\/www.huntress.com\/blog\/pups-grow-fangs\" id=\"https:\/\/www.huntress.com\/blog\/pups-grow-fangs\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Huntress researchers James Northey and Ryan Dowd identified the threat<\/a> after WMI persistence signals began triggering across managed environments. <\/p>\n<p>Tracing the activity back, they discovered a signed executable named RaceCarTwo.exe as the origin of the entire infection chain. <\/p>\n<p>From there, the attack deployed Setup.msi, which in turn executed a PowerShell script called ClockRemoval.ps1 \u2014 a powerful AV killer that not only shut down security processes but actively blocked any attempt to reinstall them.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/363ddd4b-3c36-4f63-8869-0e7e0650fd0c\/25000-Endpoints-Exposed-by-Dragon-Boss-Solutions-Update-Domain-Supply-Chain-Attack.pdf?AWSAccessKeyId=ASIA2F3EMEYE6G7GT6D3&amp;Signature=G%2BU0uMFbOSRctKBMuFsNBtNG94Y%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjENX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDKPg9t94zE1YiOu0FOiUGWoJjbj37uwUk1II9pnKIlxwIhAJz1Ym8CX54wumNE%2BqptwkW%2Fi6wzCnkXniX7w0DaMdSeKvwECJ7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgxiNA7MlLuHjZ8KoH0q0AS%2FQH%2BEvAKXaBp%2BYhjijoLWhO3yrcRWp9amNmyqbie2pEbRWwm%2FMAJUHpWgyLu5MI3G10MkDYBh1pEkKwjFo%2BJYoh48OFIc3ubLjrl47Pu9Ax2cTM5Gfjx0Hahj45uUj1KmhAwA5nD3RyHwTFSgJ41fhTP8tgCichanCJZWvKlYw3CtbFcxQtY48V%2Bn2QkB6%2BfdJpAL%2BOLLocMMtsErybfziQLmbufGdOhv1FtM61MwxNlaTwiLIpKyQgAEnMspAxkc%2BTVRPAZ7krxo6I%2B8ZNIMXQOj9v3wQCaZT3KKKDqPtDfAuHczxI3PqtQ9po22BmRrlY1kyKUuYivoaLO4Uljh3Yo1zjlC0X%2F20u0mexNOvkamQ%2F%2BLcqk9f0cVpynvhoNwNnienZ%2FStLOBPhN0pg9b%2F710m5X61AAddKBZAAbqSIA%2FE1UqhKpsKJrMffSe6mUZVS2wUbQqZ2iqaacE0%2FAHWiMmoOd%2FUa2So9m%2FgqJbw36SA5zMBCFlIxxkQD7XSr85%2ByroQGa6DFJOH9%2FBhJlg3JKd2eWND9eq9Mh9bBDOZRswUoSKNwETzHwT1NnXA2ASnBmo48k03sMC6gM8we8wePVt%2FYOUvQAGN9fa5Be1W0bqJ3bDMb5Q4obwqrIsmH%2Bk96g5Fxfr7IBd89fXiajNSV6zWewfi03Jtp3gZzznPCSWxoLiZl8GKXUbuHOIqqEPk2p%2FQq%2F6kOlTSqpDzXMSIJUkPoRdUMdHS43n4tcWtjmMCtEATtkpDTubPvptq0VtJhOZQ3qIkYcBwEpsY6PsMKOw%2FM4GOpcBhqDxOTje6woZrC9Ylv83NdlkolngRWQd7cs6ka34fuK0sMt%2BOMhm2oz9Ktqw8GJ7naiHyEcVlxxFG1ReMvCzkH6CfMb5BbB4%2FwuYnv62Q9KTefqd1oGqzs7Vu69%2BDUtHBJsYEeDY2Q0Sz0uLQ7nshj5Ap0jMTNJrXebwQyw4BHj56jfPboHWjWHN0OFDw3KO56KKB8mAiw%3D%3D&amp;Expires=1776230009\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>What made the situation especially alarming was a critical flaw baked right into the update configuration. <\/p>\n<p>The primary update domain, chromsterabrowser[.]com, was completely unregistered, meaning anyone willing to spend roughly $10 to register it would instantly gain the ability to push any payload to every infected endpoint running that software variant. <\/p>\n<p>Huntress registered the domain first, pointed it to a sinkhole, and within hours, tens of thousands of infected systems began reaching out looking for instructions \u2014 ransomware, an infostealer, or anything else entirely. <\/p>\n<p>Over a 24-hour monitoring window, 23,565 unique <a href=\"https:\/\/cybersecuritynews.com\/atlassian-servers600-ips\/\" id=\"54749\" target=\"_blank\" rel=\"noreferrer noopener\">IP addresses<\/a> connected to the sinkhole, confirming the true scale of live infections worldwide.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/363ddd4b-3c36-4f63-8869-0e7e0650fd0c\/25000-Endpoints-Exposed-by-Dragon-Boss-Solutions-Update-Domain-Supply-Chain-Attack.pdf?AWSAccessKeyId=ASIA2F3EMEYE6G7GT6D3&amp;Signature=G%2BU0uMFbOSRctKBMuFsNBtNG94Y%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjENX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDKPg9t94zE1YiOu0FOiUGWoJjbj37uwUk1II9pnKIlxwIhAJz1Ym8CX54wumNE%2BqptwkW%2Fi6wzCnkXniX7w0DaMdSeKvwECJ7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgxiNA7MlLuHjZ8KoH0q0AS%2FQH%2BEvAKXaBp%2BYhjijoLWhO3yrcRWp9amNmyqbie2pEbRWwm%2FMAJUHpWgyLu5MI3G10MkDYBh1pEkKwjFo%2BJYoh48OFIc3ubLjrl47Pu9Ax2cTM5Gfjx0Hahj45uUj1KmhAwA5nD3RyHwTFSgJ41fhTP8tgCichanCJZWvKlYw3CtbFcxQtY48V%2Bn2QkB6%2BfdJpAL%2BOLLocMMtsErybfziQLmbufGdOhv1FtM61MwxNlaTwiLIpKyQgAEnMspAxkc%2BTVRPAZ7krxo6I%2B8ZNIMXQOj9v3wQCaZT3KKKDqPtDfAuHczxI3PqtQ9po22BmRrlY1kyKUuYivoaLO4Uljh3Yo1zjlC0X%2F20u0mexNOvkamQ%2F%2BLcqk9f0cVpynvhoNwNnienZ%2FStLOBPhN0pg9b%2F710m5X61AAddKBZAAbqSIA%2FE1UqhKpsKJrMffSe6mUZVS2wUbQqZ2iqaacE0%2FAHWiMmoOd%2FUa2So9m%2FgqJbw36SA5zMBCFlIxxkQD7XSr85%2ByroQGa6DFJOH9%2FBhJlg3JKd2eWND9eq9Mh9bBDOZRswUoSKNwETzHwT1NnXA2ASnBmo48k03sMC6gM8we8wePVt%2FYOUvQAGN9fa5Be1W0bqJ3bDMb5Q4obwqrIsmH%2Bk96g5Fxfr7IBd89fXiajNSV6zWewfi03Jtp3gZzznPCSWxoLiZl8GKXUbuHOIqqEPk2p%2FQq%2F6kOlTSqpDzXMSIJUkPoRdUMdHS43n4tcWtjmMCtEATtkpDTubPvptq0VtJhOZQ3qIkYcBwEpsY6PsMKOw%2FM4GOpcBhqDxOTje6woZrC9Ylv83NdlkolngRWQd7cs6ka34fuK0sMt%2BOMhm2oz9Ktqw8GJ7naiHyEcVlxxFG1ReMvCzkH6CfMb5BbB4%2FwuYnv62Q9KTefqd1oGqzs7Vu69%2BDUtHBJsYEeDY2Q0Sz0uLQ7nshj5Ap0jMTNJrXebwQyw4BHj56jfPboHWjWHN0OFDw3KO56KKB8mAiw%3D%3D&amp;Expires=1776230009\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The geographic spread of the campaign was significant. The United States had the highest infection count with 12,697 hosts (53.9%), followed by France at 2,803 (11.9%), Canada at 2,380 (10.1%), the United Kingdom at 2,223 (9.4%), and Germany at 2,045 (8.7%). <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEior3QlZ6dWmsDzLJsXWIh6L7sYxhMtHYrQUBMU0tiZRpbHpjTdW0EhKcMzDxnKlsqqNV-mdJEUTKlH7ne0oq1fIEMaXzdBHnW7tM8qlvw7hRfAYFP8ew9sVkqF0uLk4S-ZiXRRzKJgjSFMrQU8FxutdWx8Jg2k2HxpVaCBm-BVcf8IBie2uD2kVIy_foc\/s16000\/Diagram%2520showing%2520attack%2520path%2520%28Source%2520-%2520Huntress%29.webp?ssl=1\" alt=\"Diagram showing attack path (Source - Huntress)\"><figcaption class=\"wp-element-caption\">Diagram showing attack path (Source \u2013 Huntress)<\/figcaption><\/figure>\n<\/div>\n<p>Among all infections, 324 were traced to high-value networks, including 221 universities and colleges, 41 operational technology networks tied to electric utilities and critical infrastructure, 35 government entities, 24 primary and secondary schools, and 3 healthcare organizations. Multiple Fortune 500 company networks were also among those affected.<\/p>\n<h2 class=\"wp-block-heading\" id=\"inside-the-av-killing-payload\"><strong>Inside the AV-Killing Payload<\/strong><\/h2>\n<p>The ClockRemoval.ps1 script was the core of the attack\u2019s destructive capability. Once deployed through the MSI update package, it ran a thorough sweep of the infected system \u2014 killing antivirus processes, stripping their services through registry manipulation, and creating five scheduled tasks running as SYSTEM. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEij9IdaGhEQMvA-I5e7TQSi9oHjI0Eb8NxE1RMmqToenfeHJzCKbZtDqNsbtpR1S7vFf0icmPh25t3A9SJQbeVFBpGKrDkNxJvMqCjlARJaTSPpsENLQhqTcodZTMYl421j12y4yq395AQ1ZAEiqX7upagSyADIXf9MVwNvQb46rR_FH_7RcD7zDCkJDuM\/s16000\/Synopsis%2520at%2520the%2520start%2520of%2520%21_StringData%2520-%2520ClockRemoval.ps1%2520%28Source%2520-%2520Huntress%29.webp?ssl=1\" alt=\"Synopsis at the start of !_StringData - ClockRemoval.ps1 (Source - Huntress)\"><figcaption class=\"wp-element-caption\">Synopsis at the start of !_StringData \u2013 ClockRemoval.ps1 (Source \u2013 Huntress)<\/figcaption><\/figure>\n<\/div>\n<p>These tasks \u2014 ClockSetupWmiAtBoot, DisableClockServicesFirst, DisableClockAtStartup, RemoveClockAtLogon, and RemoveClockPeriodic \u2014 ensured that security tools were removed on every boot, startup, and every 30 minutes.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjqUAVeQt21Iq8HkSkPasFGPbk7qEZUnZK5SclrhO7DZoLStjLUr550YaeKLNmn8-QnibA4_pmX8unRTDfDtP5YTQTPmDROUGT-FLqSH20o335Vg-U3xQ2MrXrSkSTPY-B6klYMYW8P0UZgib8WEz8EGcdNBqE_-d9YnuNaaEptMj2r6S4j159_d8OTCdI\/s16000\/Portion%2520of%2520function%2520Initialize-MbSetupWmiKill%2520in%2520%21_StringData%2520-%2520ClockRemoval.ps1%2520%28Source%2520-%2520Huntress%29.webp?ssl=1\" alt=\"Portion of function Initialize-MbSetupWmiKill in !_StringData - ClockRemoval.ps1 (Source - Huntress)\"><figcaption class=\"wp-element-caption\">Portion of function Initialize-MbSetupWmiKill in !_StringData \u2013 ClockRemoval.ps1 (Source \u2013 Huntress)<\/figcaption><\/figure>\n<\/div>\n<p>The script also modified the <a href=\"https:\/\/cybersecuritynews.com\/windows-11-emergency-update\/\" id=\"146306\" target=\"_blank\" rel=\"noreferrer noopener\">Windows hosts<\/a> file to redirect AV vendor update domains, including those for Malwarebytes and Kaspersky, to 0.0.0.0, cutting off all reinstallation routes. <\/p>\n<p>It added Windows Defender exclusions for paths like DGoogle, EMicrosoft, and DDapps \u2014 believed to be staging directories for future payloads. <\/p>\n<p>Dragon Boss Solutions-signed Chrome binaries were also observed running with the flag\u00a0<code>--simulate-outdated-no-au=\"01 Jan 2199\"<\/code>, permanently disabling Chrome\u2019s auto-update feature.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/363ddd4b-3c36-4f63-8869-0e7e0650fd0c\/25000-Endpoints-Exposed-by-Dragon-Boss-Solutions-Update-Domain-Supply-Chain-Attack.pdf?AWSAccessKeyId=ASIA2F3EMEYE6G7GT6D3&amp;Signature=G%2BU0uMFbOSRctKBMuFsNBtNG94Y%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjENX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDKPg9t94zE1YiOu0FOiUGWoJjbj37uwUk1II9pnKIlxwIhAJz1Ym8CX54wumNE%2BqptwkW%2Fi6wzCnkXniX7w0DaMdSeKvwECJ7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgxiNA7MlLuHjZ8KoH0q0AS%2FQH%2BEvAKXaBp%2BYhjijoLWhO3yrcRWp9amNmyqbie2pEbRWwm%2FMAJUHpWgyLu5MI3G10MkDYBh1pEkKwjFo%2BJYoh48OFIc3ubLjrl47Pu9Ax2cTM5Gfjx0Hahj45uUj1KmhAwA5nD3RyHwTFSgJ41fhTP8tgCichanCJZWvKlYw3CtbFcxQtY48V%2Bn2QkB6%2BfdJpAL%2BOLLocMMtsErybfziQLmbufGdOhv1FtM61MwxNlaTwiLIpKyQgAEnMspAxkc%2BTVRPAZ7krxo6I%2B8ZNIMXQOj9v3wQCaZT3KKKDqPtDfAuHczxI3PqtQ9po22BmRrlY1kyKUuYivoaLO4Uljh3Yo1zjlC0X%2F20u0mexNOvkamQ%2F%2BLcqk9f0cVpynvhoNwNnienZ%2FStLOBPhN0pg9b%2F710m5X61AAddKBZAAbqSIA%2FE1UqhKpsKJrMffSe6mUZVS2wUbQqZ2iqaacE0%2FAHWiMmoOd%2FUa2So9m%2FgqJbw36SA5zMBCFlIxxkQD7XSr85%2ByroQGa6DFJOH9%2FBhJlg3JKd2eWND9eq9Mh9bBDOZRswUoSKNwETzHwT1NnXA2ASnBmo48k03sMC6gM8we8wePVt%2FYOUvQAGN9fa5Be1W0bqJ3bDMb5Q4obwqrIsmH%2Bk96g5Fxfr7IBd89fXiajNSV6zWewfi03Jtp3gZzznPCSWxoLiZl8GKXUbuHOIqqEPk2p%2FQq%2F6kOlTSqpDzXMSIJUkPoRdUMdHS43n4tcWtjmMCtEATtkpDTubPvptq0VtJhOZQ3qIkYcBwEpsY6PsMKOw%2FM4GOpcBhqDxOTje6woZrC9Ylv83NdlkolngRWQd7cs6ka34fuK0sMt%2BOMhm2oz9Ktqw8GJ7naiHyEcVlxxFG1ReMvCzkH6CfMb5BbB4%2FwuYnv62Q9KTefqd1oGqzs7Vu69%2BDUtHBJsYEeDY2Q0Sz0uLQ7nshj5Ap0jMTNJrXebwQyw4BHj56jfPboHWjWHN0OFDw3KO56KKB8mAiw%3D%3D&amp;Expires=1776230009\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Security teams should hunt for WMI event subscriptions containing \u201cMbRemoval\u201d or \u201cMbSetup\u201d in the consumer name, monitor scheduled tasks pointing to WMILoad directories or ClockRemoval scripts, flag any processes signed by Dragon Boss Solutions LLC, inspect the hosts file for blocked AV vendor domains, and check <a href=\"https:\/\/cybersecuritynews.com\/windows-defender-enhancements\/\" id=\"106763\" target=\"_blank\" rel=\"noreferrer noopener\">Windows Defender<\/a> exclusion paths for suspicious entries such as DGoogle, EMicrosoft, or DDapps.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/25000-endpoints-exposed-by-dragon-boss-solutions\/\">25,000+ Endpoints Exposed by Dragon Boss Solutions Update Domain Supply Chain Attack<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/25000-endpoints-exposed-by-dragon-boss-solutions\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>25,000+ Endpoints Exposed by Dragon Boss Solutions Update Domain Supply Chain Attack What started as a routine adware alert quickly turned into something far more serious. On the morning of March 22, 2026, security alerts began firing across multiple managed environments, all linked to software signed by a company called Dragon Boss Solutions LLC. The [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-12123","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12123"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12123"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12123\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12123"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12123"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12123"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}