Dragon Boss Adware Disables Antivirus on 23,000 Hosts, Exposing Global Networks
A signed adware operation linked to Dragon Boss Solutions LLC has been disabling antivirus software on over 23,000 endpoints globally. The operation uses a legitimate code-signing certificate and an update mechanism to deploy a PowerShell-based payload that systematically disables security tools. The campaign was first observed in March 2025, with underlying loaders present since late 2024. The adware targets products from Malwarebytes, Kaspersky, McAfee, and ESET, using a script to kill antivirus processes and block reinstallation. The operation's primary update domain was unregistered, allowing potential exploitation by malicious actors.