[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$feRFJkzi2GdPpWqJPeReZ2Tkm9EN8WNh-nLLaOthI9uk":3},{"article":4,"iocs":39,"watch_terms":43},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":28},"efa904f7-efe1-402a-b04f-e0b890d656fa","'Harmless' Global Adware Transforms Into an AV Killer","harmless-global-adware-transforms-into-an-av-killer-a5d787","A benign looking update Dragon Boss pushed out in March 2025 established persistence via scheduled tasks and arranged for future payloads to be excluded from Windows Defender.","A seemingly benign update distributed by Dragon Boss adware in March 2025 contained malicious functionality that established persistence through Windows scheduled tasks and configured Windows Defender to exclude future payloads. This transformation from apparent adware to a sophisticated persistence mechanism demonstrates how legitimate-looking updates can be weaponized to create backdoors for secondary attack stages.","Dragon Boss adware March 2025 update establishes persistence and disables Windows Defender protection.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002Fharmless-global-adware-av-killer","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fbltcc23cf58a0283b13\u002F69e0fbb3eb41a9b573b1d155\u002FAdware-Artem_Medvediev-Alamy.jpg?width=1280&auto=webp&quality=80&disable=upscale","2026-04-16T19:07:26+00:00","2026-04-16T20:00:17.93888+00:00",8,[18,21],{"name":19,"type":20},"Windows Defender","product",{"name":22,"type":23},"Windows scheduled tasks","technology","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":24,"icon":11,"name":26,"slug":27},"Malware","malware",[29,34],{"category":30},{"id":31,"icon":11,"name":32,"slug":33},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":35},{"id":36,"icon":11,"name":37,"slug":38},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[40],{"type":27,"value":41,"context":42},"Dragon Boss","Adware\u002Fbackdoor malware pushing malicious updates with persistence and AV evasion capabilities",[19]]