[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMCCrXzwKPJRVzNP4UyCg6mCgWDDgTA2Ua-YBx4aIubs":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"d2eb20de-93fa-47d5-b2af-156eef86f6cf","adware-update-transforms-into-sophisticated-av-evasion-tool","efa904f7-efe1-402a-b04f-e0b890d656fa","Adware Update Transforms Into Sophisticated AV Evasion Tool","Dragon Boss adware leveraged a seemingly harmless software update to deploy malicious functionality that established persistence through Windows scheduled tasks and compromised Windows Defender protections. This incident highlights how attackers can abuse the software supply chain by weaponizing legitimate update mechanisms to bypass security controls. The transformation from benign adware to a sophisticated persistence tool demonstrates that even 'low-risk' software can become a vector for advanced threats through malicious updates.","**Immediate actions:**\n- Review and remove any Dragon Boss adware installations from organizational systems\n- Audit Windows Defender exclusion lists for unauthorized entries and remove suspicious exclusions\n- Scan all systems for unauthorized scheduled tasks and remove malicious persistence mechanisms\n\n**Supply chain security:**\n- Implement software allowlisting to prevent unauthorized applications from executing\n- Establish vendor risk assessment procedures before approving third-party software installations\n- Deploy endpoint detection tools that monitor for configuration changes to security software\n\n**Configuration hardening:**\n- Restrict administrative privileges required to modify Windows Defender settings\n- Enable tamper protection on Windows Defender to prevent unauthorized configuration changes\n- Implement group policies to centrally manage security software configurations",[12,13,14,15,16],"CIS Control 2.1","CIS Control 7.6","NIST SC-7","NIST SI-7","NIST CM-3","published","2026-04-16T20:08:57.226863+00:00","2026-04-16T20:08:57.12+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002Fharmless-global-adware-av-killer","harmless-global-adware-transforms-into-an-av-killer-a5d787","'Harmless' Global Adware Transforms Into an AV Killer",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":32,"name":33,"slug":34,"description":35,"color":36},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]