Huntress uncovered a malware operation abusing software signed by Dragon Boss Solutions LLC and its legitimate Advanced Installer update mechanism to push a multi-stage payload onto Windows systems. The chain reportedly began with RaceCarTwo.exe and Setup.msi and ended with the PowerShell script ClockRemoval.ps1, which executed with SYSTEM privileges to kill antivirus processes, disable security services, add Windows Defender exclusions, block AV vendor domains via the hosts file, and maintain persistence through WMI event subscriptions and scheduled tasks.
Researchers found that update domains including chromsterabrowser[.]com and worldwidewebframework3[.]com were left unregistered, creating a supply-chain-style takeover risk in which anyone controlling those domains could have delivered arbitrary malware through the trusted updater. Huntress registered and sinkholed the infrastructure before it could be hijacked, then recorded 23,565 unique infected hosts from 124 countries contacting the domains within 24 hours, including systems in universities, government agencies, OT networks, schools, healthcare organizations, and multiple Fortune 500 environments; the firm warned the access could have been used to deploy ransomware, infostealers, or other follow-on payloads after endpoint protections were stripped away.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
Within 24 hours of the sinkhole going live, 23,565 unique IP addresses contacted the Dragon Boss update infrastructure from 124 countries. Affected environments included universities, government entities, OT networks, schools, healthcare organizations, and multiple Fortune 500 networks.
Huntress published research detailing the Dragon Boss Solutions operation, the AV-killing payload chain, and the risk posed by the abandoned update domains. The disclosure warned that the compromised update path could have been used to deliver ransomware, infostealers, or other malware.
To prevent third-party abuse of the exposed update infrastructure, Huntress registered and sinkholed the unclaimed Dragon Boss update domains. This defensive action blocked potential malicious takeover of the software update channel.
Huntress discovered that update domains including chromsterabrowser[.]com and worldwidewebframework3[.]com were unregistered, creating a path for anyone controlling them to push arbitrary payloads to infected hosts through the trusted update mechanism. This elevated the activity from adware-like behavior to a supply-chain-style compromise risk.
A potentially unwanted program signed by Dragon Boss Solutions LLC used Advanced Installer to silently deliver a multi-stage infection chain on Windows systems. The payload culminated in ClockRemoval.ps1 running with SYSTEM privileges, establishing persistence and disabling antivirus and other security tools.
A Dragon Boss Solutions LLC software update on 2025-03-22 delivered a multi-stage payload via Advanced Installer that disabled security tools, established persistence, and configured Microsoft Defender exclusions on Windows hosts. This marked the operational deployment of the malicious behavior later documented by Huntress.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
6 references tracked. Mallory keeps watching after this page renders.
trojan-killer.net
Open sourcedarkreading.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcehuntress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.