[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAXrBf1KOAfBsIwUaCuZO7lezb_WxBedTourXgBZW5ys":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"e6cea0ca-f848-4c31-b41e-edf64586fdb0","signed-malware-campaign-exploits-trust-to-disable-enterprise-security","ed23beb0-9d9b-485e-bada-b476d929a39d","Signed Malware Campaign Exploits Trust to Disable Enterprise Security","Attackers leveraged digitally signed software from Dragon Boss Solutions LLC to deploy malicious payloads that systematically disabled antivirus protections across 23,500 hosts globally. The campaign exploited the inherent trust organizations place in code-signed applications, allowing malware to execute with SYSTEM privileges and bypass initial security screening. This supply chain compromise demonstrates how legitimate digital certificates can be weaponized to deliver sophisticated attacks that specifically target and neutralize endpoint security defenses. The widespread impact across critical infrastructure, government agencies, and educational institutions highlights the severe consequences when signed malware evades detection mechanisms.","**Immediate actions:**\n- Audit all installed software from Dragon Boss Solutions LLC and remove suspicious applications\n- Implement application control policies that go beyond certificate validation to include behavioral analysis\n- Review security product logs for signs of tampering or unexpected service disruptions\n\n**Long-term improvements:**\n- Deploy endpoint detection and response (EDR) solutions that monitor for security product manipulation\n- Establish certificate reputation monitoring to track malicious use of valid signing certificates\n- Implement network segmentation to limit lateral movement from compromised endpoints\n\n**Detection measures:**\n- Monitor PowerShell execution for scripts targeting security software processes and services\n- Set up alerts for outbound connections to security vendor domains being blocked at the endpoint level\n- Enable tamper protection features in security products to prevent unauthorized disabling",[12,13,14,15,16,17],"CIS Control 2","CIS Control 8","NIST SP 800-161","NIST CS.ID-4","NIST PR.DS-6","ISO 27001 A.14.1.2","published","2026-04-15T19:08:14.664289+00:00","2026-04-15T19:08:14.494+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fsigned-software-abused-to-deploy-antivirus-killing-scripts\u002F","signed-software-abused-to-deploy-antivirus-killing-scripts-48a9cd","Signed software abused to deploy antivirus-killing scripts",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":33,"name":34,"slug":35,"description":36,"color":37},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[39],{"id":40,"date":41,"edition":42,"title":43,"audio_url":44},"fd64ce54-a5e4-4b28-aa2b-50a3551e774c","2026-04-16","morning","ThreatNoir Morning Brief — April 16","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-04-16\u002Fthreatnoir-morning-brief-2026-04-16.mp3"]