Dragon Boss Solutions LLC is an adware and potentially unwanted program operator that claimed to be based in the United Arab Emirates. The group distributed browser- and desktop-related monetization software at scale and used an installer framework with an update mechanism to maintain access to infected systems. In March 2025, one of its updates escalated from adware behavior into overtly malicious activity by disabling or interfering with multiple security products, establishing persistence via scheduled tasks, and configuring Microsoft Defender exclusions to facilitate future payload delivery. This behavior effectively converted a large installed base of adware infections into a platform for follow-on compromise. The campaign affected more than 23,500 systems across 124 countries, with a particularly large concentration in the United States. Confirmed victim categories included government entities, operational technology environments, higher education institutions, and large enterprises including Fortune 500 companies. Infections were reported to have existed on some devices since at least 2022, and the distribution ecosystem was associated with bundled potentially unwanted programs. Operationally, Dragon Boss Solutions LLC relied on software update infrastructure embedded in its packaged applications. That architecture created downstream risk because control of the update channel could be used to push arbitrary payloads to a broad victim base. The actor's observed tradecraft supports assessment of capabilities including initial access through software distribution, persistence, defense evasion through security-tool interference and Defender exclusions, and post-exploitation preparation for additional malware deployment. Although the infrastructure could have enabled ransomware or botnet delivery, high-confidence reporting supports the observed malicious update and preparatory access rather than confirmed ransomware operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.